CVE-2024-24133: SQL Injection
Published Feb 7, 2024
·Updated
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
Affected Software
2 affected components
Atmail atmail=6.3.0
Atmail atmail=6.6.0
Event History
Feb 7, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24133?
CVE-2024-24133 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-24133?
To fix CVE-2024-24133, it's recommended to update Atmail to a version that addresses this SQL injection issue.
3
What software versions are affected by CVE-2024-24133?
CVE-2024-24133 affects Atmail versions 6.3.0 and 6.6.0.
4
What kind of attack can exploit CVE-2024-24133?
CVE-2024-24133 can be exploited through SQL injection attacks via the username parameter on the login page.
5
Is there a patch available for CVE-2024-24133?
Yes, patches are included in the latest updates for Atmail that resolve CVE-2024-24133.