CVE-2024-10946
Last modified
CVE-2024-10946 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects an unknown part of the file /interlib/admin/SysLib?cmdACT=inputLIBCODE&mod=batchXSL&xsl=editLIBCODE.xsl&libcodes=&ROWID=. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects an unknown part of the file /interlib/admin/SysLib?cmdACT=inputLIBCODE&mod=batchXSL&xsl=editLIBCODE.xsl&libcodes=&ROWID=. The manipulation of the argument sql leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Guangzhou Tuchuang | Interlib | <= 2.0.1 |
References
- https://vuldb.com/?ctiid.283365Permissions Required, VDB Entry
- https://vuldb.com/?id.283365Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.434449Third Party Advisory, VDB Entry
- https://wiki.shikangsi.com/post/share/cfb12573-ca11-433d-b9a0-fce47837a1f5Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-10946?
How severe is CVE-2024-10946?
How do I fix CVE-2024-10946?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10940A vulnerability in langchain-core versions >=0.1.17,<0.1.53,…5.3
- CVE-2024-10941A malicious website could have included an iframe with an ma…6.5
- CVE-2024-10942The All-in-One WP Migration and Backup plugin for WordPress …7.5
- CVE-2024-10943An authentication bypass vulnerability exists in the affecte…9.1
- CVE-2024-10944A Remote Code Execution vulnerability exists in the affected…8.4
- CVE-2024-10945A Local Privilege Escalation vulnerability exists in the aff…7.3
- CVE-2024-10947A vulnerability classified as critical was found in Guangzho…7.2
- CVE-2024-10948A vulnerability in the upload function of binary-husky/gpt_a…6.5
- CVE-2024-1095The Build & Control Block Patterns – Boost up Gutenberg Edit…5.3
- CVE-2024-10950In binary-husky/gpt_academic version <= 3.83, the plugin `Co…8.8
- CVE-2024-10952The The Authors List plugin for WordPress is vulnerable to a…7.3
- CVE-2024-10953An authenticated data.all user is able to perform mutating U…5.3
Are you affected by CVE-2024-10946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
