CVE-2024-24001: SQL Injection
jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass jshERP's protection mechanism.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24001?
CVE-2024-24001 has been classified with a high severity due to its potential for exploitation via SQL Injection.
How do I fix CVE-2024-24001?
To fix CVE-2024-24001, you should validate and sanitize all user inputs in the affected function to prevent malicious SQL queries.
What versions of jshERP are affected by CVE-2024-24001?
CVE-2024-24001 specifically affects jshERP version 3.3.
Can exploitation of CVE-2024-24001 lead to data breaches?
Yes, exploitation of CVE-2024-24001 can lead to unauthorized access to sensitive data in the jshERP application.
What type of vulnerability is CVE-2024-24001?
CVE-2024-24001 is an SQL Injection vulnerability that allows attackers to manipulate database queries.