CVE-2024-28145
Last modified
CVE-2024-28145 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-28145?
How severe is CVE-2024-28145?
How do I fix CVE-2024-28145?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-2814A vulnerability was found in Tenda AC15 15.03.20_multi. It h…9.8
- CVE-2024-28140The scanner device boots into a kiosk mode by default and op…6.1
- CVE-2024-28141The web application is not protected against cross-site requ…6.3
- CVE-2024-28142Due to missing input sanitization, an attacker can perform c…4.7
- CVE-2024-28143The password change function at /cgi/admin.cgi does not requ…8.4
- CVE-2024-28144An attacker who can spoof the IP address and the User-Agent …5.5
- CVE-2024-28146The application uses several hard-coded credentials to encry…8.4
- CVE-2024-28147An authenticated user can upload arbitrary files in the uplo…7.4
- CVE-2024-28148An authenticated user could potentially access metadata for …4.3
- CVE-2024-28149Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclus…6.5
- CVE-2024-2815A vulnerability classified as critical has been found in Ten…9.8
- CVE-2024-28150Jenkins HTML Publisher Plugin 1.32 and earlier does not esca…4.7
Are you affected by CVE-2024-28145?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
