CVE-2024-53505: SQL Injection
Published Nov 29, 2024
·Updated
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.
Affected Software
2 affected components
SiYuan SiYuan
b3log SiYuan=3.1.11
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53505?
CVE-2024-53505 is classified as a high severity vulnerability due to the potential for unauthorized data access through SQL injection.
2
How do I fix CVE-2024-53505?
To fix CVE-2024-53505, ensure that input validation and parameterized queries are implemented to prevent SQL injection through the id parameter.
3
Who is affected by CVE-2024-53505?
CVE-2024-53505 affects users of Siyuan version 3.1.11 who utilize the getAssetContent feature.
4
What type of vulnerability is CVE-2024-53505?
CVE-2024-53505 is a SQL injection vulnerability that allows attackers to manipulate database queries.
5
When was CVE-2024-53505 discovered?
CVE-2024-53505 was identified in the Siyuan software and reported in relation to its 3.1.11 version.