{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-6733","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-07-14T07:15:46.106Z","datePublished":"2024-07-14T23:00:05.330Z","dateUpdated":"2024-08-01T21:41:04.607Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-07-14T23:00:05.330Z"},"title":"itsourcecode Tailoring Management System templateedit.php sql injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-89","lang":"en","description":"CWE-89 SQL Injection"}]}],"affected":[{"vendor":"itsourcecode","product":"Tailoring Management System","versions":[{"version":"1.0","status":"affected"}]}],"descriptions":[{"lang":"en","value":"A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file templateedit.php. The manipulation of the argument id/title/msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271454 is the identifier assigned to this vulnerability."},{"lang":"de","value":"Eine Schwachstelle wurde in itsourcecode Tailoring Management System 1.0 gefunden. Sie wurde als kritisch eingestuft. Hierbei geht es um eine nicht exakt ausgemachte Funktion der Datei templateedit.php. Durch das Manipulieren des Arguments id/title/msg mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-07-14T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-07-14T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-07-14T09:21:06.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"jiaoyanshuai (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.271454","name":"VDB-271454 | itsourcecode Tailoring Management System templateedit.php sql injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.271454","name":"VDB-271454 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.374463","name":"Submit #374463 | itsourcecode Tailoring Management System Project In PHP 1.0 SQL Injection","tags":["third-party-advisory"]},{"url":"https://github.com/jiaoyanshuai/cve/issues/1","tags":["exploit","issue-tracking"]}]},"adp":[{"affected":[{"vendor":"itsourcecode","product":"tailoring_management_system","cpes":["cpe:2.3:a:itsourcecode:tailoring_management_system:1.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"1.0","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-15T15:24:31.790964Z","id":"CVE-2024-6733","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-16T13:25:14.119Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:41:04.607Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.271454","name":"VDB-271454 | itsourcecode Tailoring Management System templateedit.php sql injection","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.271454","name":"VDB-271454 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.374463","name":"Submit #374463 | itsourcecode Tailoring Management System Project In PHP 1.0 SQL Injection","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/jiaoyanshuai/cve/issues/1","tags":["exploit","issue-tracking","x_transferred"]}]}]}}