PT-2024-16397 · Tongda Oa · Tongda Oa

Lvzc1

·

Published

2024-10-31

·

Updated

2024-11-04

·

CVE-2024-10600

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tongda OA 2017 versions up to 11.6
Description A critical issue was found in Tongda OA, affecting an unknown function of the file pda/appcenter/submenu.php. The manipulation of the appid argument leads to sql injection. It is possible to launch the attack remotely.
Recommendations For Tongda OA 2017 versions up to 11.6, update to the latest patched version immediately to mitigate risks. As a temporary workaround, consider restricting access to the submenu.php file in the pda/appcenter directory until a patch is available. Avoid using the appid argument in the affected function until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-10600

Affected Products

Tongda Oa