# CVE-2024-10140
The script exploits a SQL Injection vulnerability found in the endpoint /php/manage_supplier.php?action=delete&id=32. The vulnerability allows an attacker to inject arbitrary SQL commands through the id parameter, potentially compromising the database and exposing sensitive information.
登录后查看神龙缓存的 POC 文件快照
登录查看