PT-2024-39548 · Unknown · Skyselang Yyladmin

0Kooo

·

Published

2024-09-27

·

Updated

2024-10-07

·

CVE-2024-9293

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions skyselang yylAdmin versions up to 3.0
Description A critical issue was found in the Backend component, specifically in the function list of the file /app/admin/controller/file/File.php. The manipulation of the is disable argument leads to SQL injection. This issue can be exploited remotely.
Recommendations For versions up to 3.0, consider restricting access to the vulnerable function list in the /app/admin/controller/file/File.php file until a patch is available. As a temporary workaround, avoid using the is disable argument in the affected function to minimize the risk of SQL injection.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-9293

Affected Products

Skyselang Yyladmin