PT-2024-5053 · Unknown · Gin-Vue-Admin
Pixelmaxqm
·
Published
2024-06-17
·
Updated
2024-06-28
·
CVE-2024-37896
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Gin-vue-admin versions 2.6.5 and earlier
Description:
The issue is related to a lack of protection against SQL query structure exploitation, allowing a remote attacker to execute arbitrary SQL queries. This occurs when the web application fails to sufficiently validate or sanitize user input, potentially leading to unauthorized database access, data leakage, manipulation, or complete database server compromise.
Recommendations:
For Gin-vue-admin versions 2.6.5 and earlier, upgrade to version 2.6.6 or later to address the SQL injection vulnerability. As a temporary workaround, consider restricting user input validation to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gin-Vue-Admin