A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.
CVSS
No CVSS.
References
Configurations
History
28 Apr 2025, 14:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.kashipara.com/project/php/12997/live-membership-system-in-php-php-project-source-code - Product | |
References | () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Live%20Membership%20System%20v1.0/SQL%20Injection.pdf - Exploit, Third Party Advisory | |
First Time |
Lopalopa
Lopalopa live Membership System |
|
CPE | cpe:2.3:a:lopalopa:live_membership_system:1.0:*:*:*:*:*:*:* |
12 Aug 2024, 13:41
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-12 13:38
Updated : 2025-04-28 14:29
NVD link : CVE-2024-40486
Mitre link : CVE-2024-40486
JSON object : View
Products Affected
lopalopa
- live_membership_system
CWE
No CWE.