CVE-2024-24256: SQL Injection
SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hrposition directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24256?
CVE-2024-24256 is classified as a high severity SQL Injection vulnerability.
How do I fix CVE-2024-24256?
To fix CVE-2024-24256, ensure that your Yonyou space-time enterprise information integration platform is updated to version 9.1 or later.
Who is affected by CVE-2024-24256?
CVE-2024-24256 affects users of Yonyou space-time enterprise information integration platform version 9.0 and earlier.
What is the impact of exploiting CVE-2024-24256?
Exploiting CVE-2024-24256 allows attackers to obtain sensitive information through SQL Injection via the gwbhAIM parameter.
Where can I find more information on CVE-2024-24256?
Further details about CVE-2024-24256 can be found in the official CVE database or vulnerability advisories.