Vulnerabilities > CVE-2024-2587 - Unspecified vulnerability in Amss++ Project Amss++ 4.31

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
amss-project

Summary

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_khet_person.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.

Vulnerable Configurations

Part Description Count
Application
Amss\+\+_Project
1