SQL Injection Strikes Again: NEWS-BUZZ Vulnerability Exposed!
NEWS-BUZZ News Management System has a SQL injection vulnerability that allows sneaky attackers to manipulate the SQL query. By simply crafting a malicious username, they can access unauthorized database actions. It’s like hacking the mainframe with a witty comment! Stay alert, and patch up your defenses before your database spills the beans.

Hot Take:
When you find out your favorite news management system has a vulnerability bigger than a plot twist in a soap opera, you know it’s time to change the channel. NEWS-BUZZ’s SQL injection flaw is the cybersecurity equivalent of leaving your front door wide open — with a sign saying “hackers welcome!”
Key Points:
- NEWS-BUZZ News Management System version 1.0 is vulnerable to SQL injection.
- The flaw is located in the login section of index.php, specifically in the handling of the username parameter.
- Attackers can manipulate SQL queries to perform unauthorized actions on the database.
- The vulnerability is demonstrated using a time-based SQL injection payload.
- CVE-2024-10758 is the official designation for this security issue.
Already a member? Log in here