CVE-2024-37871

SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the email parameter.
References
Link Resource
https://github.com/TThuyyy/cve1/issues/1 Exploit Issue Tracking Third Party Advisory
https://github.com/TThuyyy/cve1/issues/1 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:emiloi:online_discussion_forum:1.0:*:*:*:*:*:*:*

History

14 May 2025, 15:32

Type Values Removed Values Added
First Time Emiloi
Emiloi online Discussion Forum
References () https://github.com/TThuyyy/cve1/issues/1 - () https://github.com/TThuyyy/cve1/issues/1 - Exploit, Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:emiloi:online_discussion_forum:1.0:*:*:*:*:*:*:*

Information

Published : 2024-07-09 20:15

Updated : 2025-05-14 15:32


NVD link : CVE-2024-37871

Mitre link : CVE-2024-37871

CVE.ORG link : CVE-2024-37871


JSON object : View

Products Affected

emiloi

  • online_discussion_forum
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')