SQL Injection Vulnerability in /class/dbconnect.php File
CVE-2024-28145
5.9MEDIUM
Key Information:
- Vendor
Image Access Gmbh
- Status
- Vendor
- CVE Published:
- 12 December 2024
Badges
👾 Exploit Exists
What is CVE-2024-28145?
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
Affected Version(s)
Scan2Net 0
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Daniel Hirschberger (SEC Consult Vulnerability Lab)
Tobias Niemann (SEC Consult Vulnerability Lab)
