CVE-2024-53504: SQL Injection
Published Nov 29, 2024
·Updated
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.
Affected Software
2 affected components
b3log SiYuan=3.1.11
SiYuan SiYuan
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53504?
CVE-2024-53504 is classified as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-53504?
To fix CVE-2024-53504, update to the latest version of Siyuan that has addressed this vulnerability.
3
What versions of Siyuan are affected by CVE-2024-53504?
CVE-2024-53504 specifically affects Siyuan 3.1.11.
4
What potential impact does CVE-2024-53504 have?
CVE-2024-53504 can lead to unauthorized access to the database and exposure of sensitive data.
5
Where can I find more information about CVE-2024-53504?
More detailed information about CVE-2024-53504 can be found in the issues section on the Siyuan GitHub repository.