SQL Injection Vulnerability in dingfanzu CMS File Component
CVE-2024-9294

Currently unrated

Key Information:

Vendor
dingfanzu
Vendor
CVE Published:
27 September 2024

Summary

A critical SQL injection vulnerability has been identified in the dingfanzu CMS, specifically related to the functionality within the saveNewPwd.php file. This flaw occurs when manipulating the 'username' parameter, potentially allowing attackers to execute malicious SQL queries against the database. The vulnerability can be exploited remotely, raising significant concerns for application security. Due to the continuous delivery model employed by dingfanzu, there are currently no specific version details available for affected or updated releases, making it imperative for users to assess their installations closely and implement necessary mitigations as soon as possible.

References

Timeline

  • Vulnerability published

.
CVE-2024-9294 : SQL Injection Vulnerability in dingfanzu CMS File Component | SecurityVulnerability.io