CVE-2024-31009: SQL Injection
Published Apr 3, 2024
·Updated
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms=4.8
Event History
Apr 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31009?
CVE-2024-31009 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2024-31009?
To fix CVE-2024-31009, update SEMCMS to the latest version where the vulnerability is addressed.
3
What impact does CVE-2024-31009 have on my system?
CVE-2024-31009 allows remote attackers to obtain sensitive information from the application.
4
Which versions of SEMCMS are affected by CVE-2024-31009?
SEMCMS v.4.8 is the only version confirmed to be affected by CVE-2024-31009.
5
How can I detect if my system is vulnerable to CVE-2024-31009?
You can detect CVE-2024-31009 by testing for SQL injection through the lgid parameter in Banner.php.