First published: Fri Mar 01 2024(Updated: )
A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown processing of the file ?r=tmall/admin/user/1/1. The manipulation of the argument orderBy leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255389 was assigned to this vulnerability.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mini-Tmall | <=20231017 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2074 is classified as critical due to its potential to allow remote SQL injection.
To fix CVE-2024-2074, update your Mini-Tmall software to a version released after 20231017.
CVE-2024-2074 is an SQL injection vulnerability affecting the orderBy argument.
Yes, CVE-2024-2074 allows for remote exploitation due to the nature of the SQL injection.
CVE-2024-2074 affects the Mini-Tmall software versions up to and including 20231017.