DedeBIZ makehtml_freelist_action.php sql injection
CVE-2024-0558
Key Information:
Badges
What is CVE-2024-0558?
A vulnerability has been identified in the DedeBIZ application version 6.3.0, which allows for SQL injection through improper handling of the 'startid' argument in the /admin/makehtml_freelist_action.php file. This flaw enables attackers to manipulate database queries by injecting malicious SQL code, potentially leading to unauthorized access and data compromise. The vulnerability may be exploited remotely, and while the vendor was notified prior to the public disclosure, there has been no response or patch provided to address this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
DedeBIZ 6.3.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
