CVE-2024-37843: SQL Injection
Published Jun 25, 2024
·Updated
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
Affected Software
2 affected components
composer/craftcms/cms<=3.7.31
Craft CMS<3.7.31
Event History
Jun 25, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-37843?
CVE-2024-37843 has been classified as a high severity vulnerability due to the potential for SQL injection.
2
How do I fix CVE-2024-37843?
To fix CVE-2024-37843, upgrade Craft CMS to a version higher than 3.7.31.
3
What are the potential impacts of CVE-2024-37843?
CVE-2024-37843 may allow attackers to execute arbitrary SQL queries, which could compromise the database.
4
Is CVE-2024-37843 applicable to older versions of Craft CMS?
Yes, CVE-2024-37843 affects all Craft CMS versions up to and including 3.7.31.
5
How can I identify if my installation is vulnerable to CVE-2024-37843?
You can identify if your installation is vulnerable to CVE-2024-37843 by checking the version of Craft CMS you are running.