CVE-2024-11025: SMA: SQL injection in Sunny Central UP
An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administration panel to gain read and write access to a specific log file of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11025?
CVE-2024-11025 is considered a high-severity vulnerability due to the potential for unauthorized access to log files.
How can I fix CVE-2024-11025?
To mitigate CVE-2024-11025, it is recommended to sanitize user input and implement proper access controls in the administration panel.
What type of vulnerability is CVE-2024-11025?
CVE-2024-11025 is a SQL Injection vulnerability that allows an attacker to manipulate queries and access sensitive data.
Who is affected by CVE-2024-11025?
CVE-2024-11025 affects users of Sunny Central UP products that have an administration panel exposed to authenticated low-privilege users.
What can an attacker achieve by exploiting CVE-2024-11025?
An attacker exploiting CVE-2024-11025 can gain unauthorized read and write access to specific log files on the affected device.