PT-2024-24820 · Cyberpower · Cyberpower Powerpanel Enterprise

Published

2024-05-09

·

Updated

2026-05-25

·

CVE-2024-32739

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CyberPower PowerPanel Enterprise versions prior to 2.8.3
Description A SQL injection allows an unauthenticated remote attacker to leak sensitive information. This occurs through the query ptask verbose() function within MCUDBHelper.
Recommendations Update to version 2.8.3 or later. As a temporary workaround, restrict access to the query ptask verbose() function to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-32739

Affected Products

Cyberpower Powerpanel Enterprise