SQL Injection Vulnerability in Tongda OA Product
CVE-2024-4903
Key Information:
Badges
Summary
A significant SQL injection vulnerability exists in the Tongda OA 2017 application, specifically within the delete.php file located in the /general/meeting/manage/ directory. This flaw allows an attacker to manipulate the M_ID_STR parameter, potentially leading to unauthorized access and manipulation of the database. The vulnerability can be exploited remotely, heightening concerns about data security. Public disclosure of this exploit has raised alarms, especially since the vendor has not responded to initial reports of the issue. Organizations using this product should take immediate steps to mitigate the risks associated with this vulnerability.
Affected Version(s)
OA 2017
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved