SQL Injection Vulnerability in Pear Admin Boot Product
CVE-2024-6241
Key Information:
- Vendor
- Pear Admin Boot
- Status
- Pear Admin Boot
- Vendor
- CVE Published:
- 21 June 2024
Badges
Summary
A serious SQL injection vulnerability has been identified in the Pear Admin Boot product, specifically in the function getDictItems located in /system/dictData/getDictItems/. This vulnerability allows attackers to manipulate the input parameters, leading to unauthorized access and potential data leakage. Attackers can exploit this flaw remotely, making it critical for users to apply necessary security patches immediately. The vulnerability has been publicly disclosed, and the potential for exploitation has raised significant concerns regarding the security of databases relying on this application. Ensure that you assess and implement necessary measures to protect your systems from this threat.
Affected Version(s)
Pear Admin Boot 2.0.0
Pear Admin Boot 2.0.1
Pear Admin Boot 2.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published