VYPR
Critical severity9.8NVD Advisory· Published Jun 13, 2024· Updated Jun 17, 2026

CVE-2024-37849

CVE-2024-37849

Description

A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.

Affected products

3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.