• caglararli@hotmail.com
  • 05386281520

CVE-2024-24572 | WillyXJ facileManager up to 4.5.0 Parameter admin-logs.php extract $_REQUEST sql injection (GHSA-xw34-8pj6-75gc)

Çağlar Arlı      -    14 Views

CVE-2024-24572 | WillyXJ facileManager up to 4.5.0 Parameter admin-logs.php extract $_REQUEST sql injection (GHSA-xw34-8pj6-75gc)

A vulnerability classified as critical was found in WillyXJ facileManager up to 4.5.0. Affected by this vulnerability is the function extract of the file admin-logs.php of the component Parameter Handler. The manipulation of the argument $_REQUEST leads to sql injection. This vulnerability is known as CVE-2024-24572. The attack can be launched remotely. There is no exploit available. It is recommended to apply a patch to fix this issue.