216.73.217.24

CVE-2024-28145

· Published 12/12/2024 14:15 · Modified 13/12/2024 17:15

Labels: CVE-2024-28145 2024-12-12551230f0-3615-47bd-b7cc-93e92e730bbfCVE-2024-28145CWE-89

Essential information

Published
12/12/2024 14:15
Modified
13/12/2024 17:15
Author
Creator
CVSS
5.9 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
551230f0-3615-47bd-b7cc-93e92e730bbf
NVD
View on NVD

References