CVE-2024-37858: ORETNOM23 Lost And Found Information System
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.
Affected products
- ORETNOM23 Lost And Found Information System: version 1.0 only
Published 2024-07-29. Last modified 2026-07-09.