CVE-2024-31010: SQL Injection
Published Apr 3, 2024
·Updated
SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Banner.php.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms=4.8
Event History
Apr 3, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31010?
CVE-2024-31010 is classified as a high-severity SQL injection vulnerability.
2
How do I fix CVE-2024-31010?
To fix CVE-2024-31010, ensure that all user inputs are properly validated and sanitize the ID parameter in Banner.php.
3
What kind of attack can exploit CVE-2024-31010?
CVE-2024-31010 can be exploited by a remote attacker to execute SQL injection attacks and obtain sensitive information.
4
Which version of SEMCMS is affected by CVE-2024-31010?
CVE-2024-31010 affects SEMCMS version 4.8 and potentially earlier versions.
5
What information can be compromised by CVE-2024-31010?
CVE-2024-31010 allows attackers to obtain sensitive information from the database through the vulnerable ID parameter.