PT-2024-25124 · Roothub · Roothub

Published

2024-05-07

·

Updated

2024-12-09

·

CVE-2024-33122

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Roothub version 2.6
Description The issue is related to a SQL injection vulnerability. This vulnerability occurs via the topic parameter in the list() function.
Recommendations For Roothub version 2.6, consider restricting the use of the list() function until a patch is available. As a temporary workaround, avoid using the topic parameter in the affected function to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-33122

Affected Products

Roothub