PT-2024-5053 · Unknown · Gin-Vue-Admin

Pixelmaxqm

·

Published

2024-06-17

·

Updated

2024-06-28

·

CVE-2024-37896

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Gin-vue-admin versions 2.6.5 and earlier
Description: The issue is related to a lack of protection against SQL query structure exploitation, allowing a remote attacker to execute arbitrary SQL queries. This occurs when the web application fails to sufficiently validate or sanitize user input, potentially leading to unauthorized database access, data leakage, manipulation, or complete database server compromise.
Recommendations: For Gin-vue-admin versions 2.6.5 and earlier, upgrade to version 2.6.6 or later to address the SQL injection vulnerability. As a temporary workaround, consider restricting user input validation to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05580
CVE-2024-37896
GHSA-GF3R-H744-MQGP
GO-2024-2928

Affected Products

Gin-Vue-Admin