CVE-2024-28145 - CERT CVE
ID CVE-2024-28145
Sažetak An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
Reference
CVSS
Base: 5.9
Impact: 3.4
Exploitability:2.5
Pristup
VektorSloženostAutentikacija
LOCAL LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW LOW
CVSS vektor CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Zadnje važnije ažuriranje 13-12-2024 - 17:15
Objavljeno 12-12-2024 - 14:15