TreasureHuntGame TreasureHunt acesso.php sql injection
Vulnerability Description
A vulnerability, which was classified as critical, was found in TreasureHuntGame TreasureHunt up to 963e0e0. Affected is an unknown function of the file TreasureHunt/acesso.php. The manipulation of the argument usuario leads to sql injection. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The name of the patch is 8bcc649abc35b7734951be084bb522a532faac4e. It is recommended to apply a patch to fix this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12894
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- VulDB GitHub Commit Analyzer
References
More from TreasureHuntGame
View All →Affected Vendor
TreasureHuntGame
View all reports →