SQL Injection Vulnerability in dingfanzu CMS File Component
CVE-2024-9294
Currently unrated
Summary
A critical SQL injection vulnerability has been identified in the dingfanzu CMS, specifically related to the functionality within the saveNewPwd.php file. This flaw occurs when manipulating the 'username' parameter, potentially allowing attackers to execute malicious SQL queries against the database. The vulnerability can be exploited remotely, raising significant concerns for application security. Due to the continuous delivery model employed by dingfanzu, there are currently no specific version details available for affected or updated releases, making it imperative for users to assess their installations closely and implement necessary mitigations as soon as possible.
References
Timeline
Vulnerability published