PT-2024-38074 · Netease Youdao · Qanything

Published

2024-10-13

·

Updated

2024-10-15

·

CVE-2024-7099

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions netease-youdao/qanything version 1.4.1
Description The issue concerns a SQL injection vulnerability where unsafe data obtained from user input is concatenated in SQL queries. This affects functions including get knowledge base name, from status to status, delete files, and get file by status. An attacker can exploit this to execute arbitrary SQL queries, potentially stealing database information.
Recommendations To resolve the issue, update to version 1.4.2. As a temporary workaround, consider restricting the use of the affected functions until the update is applied. Avoid using user input in SQL queries without proper sanitization to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7099

Affected Products

Qanything