PT-2024-38416 · Datagear · Datagear

Nerowander

·

Published

2024-08-06

·

Updated

2024-08-07

·

CVE-2024-7552

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataGear versions up to 5.0.0
Description A critical issue has been found, affecting the evaluateVariableExpression function of the ConversionSqlParamValueMapper.java file in the Data Schema Page component. This issue leads to improper neutralization of special elements used in an expression language statement, allowing for remote attacks.
Recommendations For DataGear versions up to 5.0.0, consider disabling the evaluateVariableExpression function as a temporary workaround until a patch is available. Restrict access to the Data Schema Page component to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-7552

Affected Products

Datagear