CVE-2024-1012
Last modified
CVE-2024-1012 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. EPSS estimates a 0.92% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The manipulation of the argument recordId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252281 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Whir | Ezoffice | 11.1.0 |
References
- https://vuldb.com/?ctiid.252281Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.252281Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?ctiid.252281Permissions Required, Third Party Advisory, VDB Entry
- https://vuldb.com/?id.252281Permissions Required, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-1012?
How severe is CVE-2024-1012?
How do I fix CVE-2024-1012?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10114The WooCommerce - Social Login plugin for WordPress is vulne…8.1
- CVE-2024-10115Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2024-10116The Twitter Follow Button plugin for WordPress is vulnerable…5.4
- CVE-2024-10117The WP Crowdfunding plugin for WordPress is vulnerable to St…5.4
- CVE-2024-10118SECOM WRTR-304GN-304TW-UPSC does not properly filter user in…9.8
- CVE-2024-10119The wireless router WRTM326 from SECOM does not properly val…9.8
- CVE-2024-10120A vulnerability has been found in wfh45678 Radar up to 1.0.8…9.8
- CVE-2024-10121A vulnerability was found in wfh45678 Radar up to 1.0.8 and …9.8
- CVE-2024-10122A vulnerability was found in Topdata Inner Rep Plus WebServe…4.9
- CVE-2024-10123A vulnerability was found in Tenda AC8 16.03.34.06. It has b…8.8
- CVE-2024-10124The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommer…9.8
- CVE-2024-10125The Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo…7.5
Are you affected by CVE-2024-1012?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
