PT-2024-38074 · Netease Youdao · Qanything
Published
2024-10-13
·
Updated
2024-10-15
·
CVE-2024-7099
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
netease-youdao/qanything version 1.4.1
Description
The issue concerns a SQL injection vulnerability where unsafe data obtained from user input is concatenated in SQL queries. This affects functions including
get knowledge base name, from status to status, delete files, and get file by status. An attacker can exploit this to execute arbitrary SQL queries, potentially stealing database information.Recommendations
To resolve the issue, update to version 1.4.2. As a temporary workaround, consider restricting the use of the affected functions until the update is applied. Avoid using user input in SQL queries without proper sanitization to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qanything