CVE-2024-10735 – Project Worlds Life Insurance Management System editNominee.php sql injection
https://notcve.org/view.php?id=CVE-2024-10735
A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /editNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can be initiated remotely. • https://github.com/GKb0y/Cve-report/blob/main/SQLi-life-insurance-management-system.md https://vuldb.com/?ctiid.282904 https://vuldb.com/?id.282904 https://vuldb.com/?submit.435424 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •
CVE-2024-10734 – Project Worlds Life Insurance Management System editPayment.php sql injection
https://notcve.org/view.php?id=CVE-2024-10734
A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /editPayment.php. The manipulation of the argument recipt_no leads to sql injection. It is possible to initiate the attack remotely. • https://github.com/peteryang520/Cve-report/blob/main/SQLi-1.md https://vuldb.com/?ctiid.282903 https://vuldb.com/?id.282903 https://vuldb.com/?submit.435410 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •