SQL Injection Vulnerability in dingfanzu CMS File Component
CVE-2024-9294

Currently unrated

Key Information:

Vendor

dingfanzu

Vendor
CVE Published:
27 September 2024

What is CVE-2024-9294?

A critical SQL injection vulnerability has been identified in the dingfanzu CMS, specifically related to the functionality within the saveNewPwd.php file. This flaw occurs when manipulating the 'username' parameter, potentially allowing attackers to execute malicious SQL queries against the database. The vulnerability can be exploited remotely, raising significant concerns for application security. Due to the continuous delivery model employed by dingfanzu, there are currently no specific version details available for affected or updated releases, making it imperative for users to assess their installations closely and implement necessary mitigations as soon as possible.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

.