CVE-2024-36800: SQL Injection
Published Jun 4, 2024
·Updated
A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.
Affected Software
2 affected components
SEMCMS SEMCMS
Sem-cms Semcms=4.8
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 4, 2024
CVE Published
via NVD·01:15 PM
Aug 22, 2024
Data Sourced
via MITRE·07:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36800?
CVE-2024-36800 is considered a critical SQL injection vulnerability.
2
How do I fix CVE-2024-36800?
To fix CVE-2024-36800, update SEMCMS to the latest version where the vulnerability is patched.
3
What kind of data can be accessed through CVE-2024-36800?
CVE-2024-36800 allows attackers to obtain sensitive information through the ID parameter in Download.php.
4
Who is affected by CVE-2024-36800?
SEMCMS version 4.8 is affected by CVE-2024-36800, making any installations of this version vulnerable.
5
How does CVE-2024-36800 exploit SQL injection?
CVE-2024-36800 exploits SQL injection by manipulating the ID parameter, allowing unauthorized database queries.