CVE-2024-35584
🟠 Łataj w tym tygodniu
Wstrzyknięcie SQL w OpenSis Community Edition umożliwia atakującym wykonanie złośliwych zapytań.
CVSS
8.8
EPSS
5.7%
Exploit
poc
Vendor
os4ed
Opis źródłowy (NVD)
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
exploit sql-injection
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.7% |
| Opublikowano (NVD) | 2024-10-15 19:15:16 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-05 16:18:54 UTC |
Referencje
- https://github.com/whwhwh96/CVE-2024-35584 (cve@mitre.org) [Exploit, Third Party Advisory]