PT-2024-16398 · Tongda Oa · Tongda Oa

·

CVE-2024-10601

·

Published

2024-10-31

·

Updated

2024-11-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tongda OA versions 2017 up to 11.10
Description A critical issue has been found in Tongda OA, affecting an unknown functionality of the file /general/address/private/address/query/delete.php. The manipulation of the where repeat argument leads to SQL injection. The attack can be launched remotely.
Recommendations For Tongda OA versions 2017 up to 11.10, update to a version that is not affected by this issue. As a temporary workaround, consider restricting access to the /general/address/private/address/query/delete.php file until a patch is available. Avoid using the where repeat argument in the affected file until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10601

Affected Products

Tongda Oa