CVE-2024-57435: Null Pointer Dereference
In macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereference occurring in all subsequent operations that require authentication, which triggers a denial-of-service attack and service restart failure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57435?
CVE-2024-57435 is classified as a denial-of-service vulnerability that can cause significant service disruptions.
How do I fix CVE-2024-57435?
To fix CVE-2024-57435, ensure input validation for the resource creation interface to prevent null data submission.
What type of attack does CVE-2024-57435 enable?
CVE-2024-57435 enables a denial-of-service attack through null pointer dereferences.
Who is affected by CVE-2024-57435?
CVE-2024-57435 affects users of macrozheng mall-tiny version 1.0.1.
What happens if CVE-2024-57435 is exploited?
Exploitation of CVE-2024-57435 leads to service restart failures and the inability to authenticate subsequent operations.