CVE-2024-25220 is a critical SQL injection vulnerability in Task Manager App v1.0, specifically affecting the taskID parameter in EditTask.php. This flaw allows unauthenticated attackers to remotely execute arbitrary SQL commands with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. While no public exploits, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score of 76/100 suggests significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:code-projects:task_manager:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.