CVE-2024-24004: SQL Injection
jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter column and order parameters well enough, and an attacker can construct malicious payload to bypass jshERP's protection mechanism in safeSqlParse method for sql injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24004?
The severity of CVE-2024-24004 is considered high due to its potential for SQL injection attacks.
How do I fix CVE-2024-24004?
To fix CVE-2024-24004, ensure that the jshERP application properly sanitizes and validates the 'column' and 'order' parameters in the findInOutDetail() function.
Which versions of jshERP are affected by CVE-2024-24004?
CVE-2024-24004 affects jshERP version 3.3.
What type of vulnerability is CVE-2024-24004?
CVE-2024-24004 is classified as an SQL Injection vulnerability.
Can exploiting CVE-2024-24004 lead to data breaches?
Yes, exploiting CVE-2024-24004 can potentially allow attackers to access sensitive data in the database.