
SQL injection exploit script targeting CVE-2024-10140 in the /php/manage_supplier.php endpoint, enabling arbitrary SQL command injection via the id parameter to compromise databases and extract sensitive data.
The script exploits a SQL Injection vulnerability found in the endpoint /php/manage_supplier.php?action=delete&id=32. The vulnerability allows an attacker to inject arbitrary SQL commands through the id parameter, potentially compromising the database and exposing sensitive information.