CVE-2024-25722: SQL Injection
Published Feb 11, 2024
·Updated
qanythingkernel/connector/database/mysql/mysqlclient.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.
Affected Software
1 affected component
qanything qanything<1.2.0
Remediation
Event History
Feb 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25722?
CVE-2024-25722 has a high severity rating due to its potential for SQL Injection vulnerabilities in QAnything before version 1.2.0.
2
How do I fix CVE-2024-25722?
To fix CVE-2024-25722, upgrade QAnything to version 1.2.0 or later where the SQL Injection vulnerability is resolved.
3
What does CVE-2024-25722 affect?
CVE-2024-25722 affects all versions of QAnything prior to 1.2.0, specifically the mysql_client.py component.
4
What is SQL Injection in context of CVE-2024-25722?
SQL Injection in CVE-2024-25722 allows attackers to manipulate database queries through improper handling of user input.
5
Is there any workaround for CVE-2024-25722?
The recommended action for CVE-2024-25722 is to upgrade to the patched version, as no reliable workaround is known.