
CVE-2024-10735 – Project Worlds Life Insurance Management System editNominee.php sql injection
https://notcve.org/view.php?id=CVE-2024-10735
03 Nov 2024 — A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /editNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can be initiated remotely. • https://github.com/GKb0y/Cve-report/blob/main/SQLi-life-insurance-management-system.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2024-10734 – Project Worlds Life Insurance Management System editPayment.php sql injection
https://notcve.org/view.php?id=CVE-2024-10734
03 Nov 2024 — A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /editPayment.php. The manipulation of the argument recipt_no leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/peteryang520/Cve-report/blob/main/SQLi-1.md • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •