First published: Fri Feb 16 2024(Updated: )
Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tongda OA | >=2017<11.9 | |
Tongda OA | >=11.0<11.10 | |
Tongda OA | =2017 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25320 is considered a critical vulnerability that allows SQL injection through the $AFF_ID parameter.
To fix CVE-2024-25320, you should validate and sanitize all user inputs in the affected parameter to prevent SQL injection.
CVE-2024-25320 affects Tongda OA versions from 2017 up to version 11.9.
SQL injection in CVE-2024-25320 refers to an attack that manipulates SQL queries by injecting malicious SQL code via the $AFF_ID parameter.
Exploitation of CVE-2024-25320 could allow an attacker to gain unauthorized access to the database, potentially exposing sensitive information.