PT-2022-16918 · Unknown · Gin-Vue-Admin+1

Piexlmax

·

Published

2022-04-13

·

Updated

2023-03-01

·

CVE-2022-24844

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gin-vue-admin versions prior to 2.5.1
Description The issue occurs in the server/service/system/sys auto code pgsql.go code, which means PostgreSQL must be used as the database for this problem to occur. Users must have JWT login and be using PostgreSQL to be affected.
Recommendations For versions prior to 2.5.1, update to version 2.5.1 to resolve the issue. As a temporary workaround, consider disabling the sys auto code pgsql.go service until a patch is available. Restrict access to the PostgreSQL database to minimize the risk of exploitation. Avoid using the JWT login feature in conjunction with PostgreSQL until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-24844
GHSA-5G92-6HPP-W425

Affected Products

Gin-Vue-Admin
Postgresql