SQL Injection Vulnerability in Tongda OA 2017
CVE-2024-10602
Key Information:
Badges
What is CVE-2024-10602?
A security vulnerability has been identified within the Tongda OA 2017 system, specifically affecting the functionality associated with the file /general/approve_center/list/input_form/data_picker_link.php. This flaw enables attackers to exploit the 'dataSrc' argument, leading to SQL injection attacks. Such exploits can be executed remotely, allowing unauthorized access to the database, potential data breaches, and system manipulation. The details of the vulnerability have been publicly disclosed, heightening the urgency for affected users to implement protective measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OA 2017 11.0
OA 2017 11.1
OA 2017 11.2
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
