CVE-2024-24019: SQL Injection
Published Feb 7, 2024
·Updated
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list
Affected Software
2 affected components
xxyopen Novel-Plus<=4.2.0
xxyopen Novel-Plus=4.3.0-rc1
Event History
Feb 7, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24019?
CVE-2024-24019 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-24019?
To fix CVE-2024-24019, upgrade to Novel-Plus version 4.3.0-RC2 or later.
3
What are the potential impacts of CVE-2024-24019?
Exploiting CVE-2024-24019 can allow attackers to execute arbitrary SQL queries, leading to data leakage or manipulation.
4
Which versions of Novel-Plus are affected by CVE-2024-24019?
CVE-2024-24019 affects Novel-Plus versions 4.3.0-RC1 and all prior versions.
5
How can SQL injection attacks occur in CVE-2024-24019?
SQL injection in CVE-2024-24019 can occur through crafted offset, limit, and sort parameters sent to the /system/roleDataPerm/list endpoint.