CVE-2024-24002: SQL Injection
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter column and order parameters well enough, and an attacker can construct malicious payload to bypass jshERP's protection mechanism in safeSqlParse method for sql injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24002?
CVE-2024-24002 is classified as a medium severity SQL Injection vulnerability.
How do I fix CVE-2024-24002?
To fix CVE-2024-24002, ensure that the input parameters 'column' and 'order' in MaterialController are properly validated and sanitized.
What software versions are affected by CVE-2024-24002?
CVE-2024-24002 affects jshERP version 3.3.
What type of vulnerability is CVE-2024-24002?
CVE-2024-24002 is an SQL Injection vulnerability.
What are the potential impacts of exploiting CVE-2024-24002?
Exploitation of CVE-2024-24002 can allow attackers to access or manipulate the database, leading to data breaches.