PT-2024-24323 · Unknown · Sonic Shopfloor.Guide
Moritz Ãhrlein
·
Published
2024-05-08
·
Updated
2024-07-03
·
CVE-2024-31961
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sonic Shopfloor.guide versions prior to 3.1.3
Description
A SQL injection issue in unit.php allows remote attackers to execute arbitrary SQL commands via the
level2 parameter. This enables attackers to manipulate database queries, potentially leading to unauthorized data access or modification.Recommendations
For versions prior to 3.1.3, update to version 3.1.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
unit.php file or validating and sanitizing the level2 parameter to prevent malicious input.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sonic Shopfloor.Guide