CVE-2024-53507: SQL Injection
Published Nov 29, 2024
·Updated
A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.
Affected Software
2 affected components
SiYuan SiYuan
b3log SiYuan=3.1.11
Event History
Nov 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53507?
CVE-2024-53507 is considered a high-severity vulnerability due to its SQL injection nature.
2
How do I fix CVE-2024-53507?
To fix CVE-2024-53507, update your Siyuan software to version 3.1.12 or later.
3
What impact does CVE-2024-53507 have on my system?
CVE-2024-53507 can allow an attacker to execute arbitrary SQL commands, potentially compromising the database.
4
In which versions of Siyuan is CVE-2024-53507 found?
CVE-2024-53507 is found in Siyuan version 3.1.11.
5
Is CVE-2024-53507 being actively exploited in the wild?
There are no public reports indicating that CVE-2024-53507 is actively being exploited in the wild.