CVE-2024-24323: SQL Injection
Published Feb 27, 2024
·Updated
SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.
Affected Software
2 affected components
linlinjava litemall
linlinjava litemall<=1.8.0
Event History
Feb 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24323?
CVE-2024-24323 is classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2024-24323?
To fix CVE-2024-24323, validate and sanitize all user inputs for the affected parameters in AdminOrdercontroller.java.
3
Which versions of linlinjava litemall are affected by CVE-2024-24323?
CVE-2024-24323 affects linlinjava litemall version 1.8.0.
4
What type of attack can exploit CVE-2024-24323?
CVE-2024-24323 can be exploited by remote attackers to execute SQL injection attacks.
5
What information can be compromised due to CVE-2024-24323?
CVE-2024-24323 allows attackers to obtain sensitive information through specific user parameters.