Gin-vue-admin SQL Injection Vulnerability
CVE-2024-37896
What is CVE-2024-37896?
The Gin-vue-admin is a management system built on Vue and Gin. A vulnerability exists in versions up to v2.6.5 that allows SQL injection due to insufficient validation or sanitization of user input in SQL queries. This flaw can enable attackers to input malicious SQL commands through seemingly harmless form fields, leading to potential unauthorized access to the database, data leakage, and manipulation. Furthermore, without proper restrictions on user input, the possibility of complete database server compromise arises. The vulnerability has been addressed in version 2.6.6, following the amendment made in commit 53d033821. Users are strongly advised to upgrade as there are currently no viable workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
gin-vue-admin < 2.6.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
