CVE-2024-30938: SQL Injection
Published Apr 18, 2024
·Updated
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMSUser.php component.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms=4.8
Event History
Apr 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Apr 19, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30938?
CVE-2024-30938 has been classified as a medium severity SQL Injection vulnerability.
2
How do I fix CVE-2024-30938?
To fix CVE-2024-30938, update SEMCMS to the latest version that addresses this SQL Injection issue.
3
What component is affected by CVE-2024-30938?
CVE-2024-30938 affects the SEMCMS_User.php component of SEMCMS v.4.8.
4
What kind of attack can be executed through CVE-2024-30938?
An attacker can exploit CVE-2024-30938 to perform SQL Injection attacks and obtain sensitive information via the ID parameter.
5
Who is affected by CVE-2024-30938?
Users of SEMCMS v.4.8 are affected by CVE-2024-30938 due to its SQL Injection vulnerability.