CVE-2024-35584
Last modified
CVE-2024-35584 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. EPSS estimates a 5.90% chance of exploitation in the next 30 days.
Description
SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the lack to sanitisation. The application takes arbitrary value from "X-Forwarded-For" header and appends it to a SQL INSERT statement directly, leading to SQL Injection.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Os4ed | Opensis | 8.0 |
| Os4ed | Opensis | 9.1 |
References
- https://github.com/whwhwh96/CVE-2024-35584Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-35584?
How severe is CVE-2024-35584?
How do I fix CVE-2024-35584?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-35579Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv…7.7
- CVE-2024-3558The Custom Field Suite plugin for WordPress is vulnerable to…5.4
- CVE-2024-35580Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.…9.8
- CVE-2024-35581A cross-site scripting (XSS) vulnerability in Sourcecodester…6.1
- CVE-2024-35582A cross-site scripting (XSS) vulnerability in Sourcecodester…6.1
- CVE-2024-35583A cross-site scripting (XSS) vulnerability in Sourcecodester…6.1
- CVE-2024-3559The Custom Field Suite plugin for WordPress is vulnerable to…5.4
- CVE-2024-35591An arbitrary file upload vulnerability in O2OA v8.3.8 allows…5.4
- CVE-2024-35592An arbitrary file upload vulnerability in the Upload functio…9.6
- CVE-2024-35593An arbitrary file upload vulnerability in the File preview f…5.5
- CVE-2024-35595An arbitrary file upload vulnerability in the File Preview f…6.1
- CVE-2024-3560The LearnPress – WordPress LMS Plugin plugin for WordPress i…5.4
Are you affected by CVE-2024-35584?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
