CVE-2024-24110: SQL Injection
Published Feb 29, 2024
·Updated
SQL Injection vulnerability in crmebjava before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET request to the component /api/front/spread/people.
Affected Software
2 affected components
crmeb crmeb_java<1.3.4
crmeb CRMEB Java<1.3.4
Event History
Feb 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 21, 2024
Data Sourced
via NVD·02:52 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What types of attacks can CVE-2024-24110 facilitate?
CVE-2024-24110 can facilitate SQL injection attacks, allowing attackers to execute arbitrary SQL commands.
2
What component is affected by CVE-2024-24110?
The /api/front/spread/people component is affected by CVE-2024-24110.
3
What is the maximum vulnerable version for CVE-2024-24110?
The maximum vulnerable version for CVE-2024-24110 is any version before 1.3.4.
4
How can I fix CVE-2024-24110?
To fix CVE-2024-24110, upgrade crmeb_java to version 1.3.4 or later.
5
Who is the vendor associated with CVE-2024-24110?
The vendor associated with CVE-2024-24110 is ZhongBangKeJi CRMEB.