CVE-2024-6039: Feng Office Workspaces sql injection
Published Jun 16, 2024
·Updated
A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-268752.
Affected Software
1 affected component
Fengoffice Feng Office=3.11.1.2
Event History
Jun 16, 2024
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 10, 2025
Exploit Published
12:00 AM
Known Exploited
09:48 AM
Apr 18, 58462
Event
via NVD·01:35 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-6039?
CVE-2024-6039 is classified as a critical vulnerability.
2
How do I fix CVE-2024-6039?
To fix CVE-2024-6039, upgrade to a patched version of Feng Office beyond 3.11.1.2.
3
What component is affected by CVE-2024-6039?
CVE-2024-6039 affects the Workspaces component of Feng Office.
4
What type of vulnerability is CVE-2024-6039?
CVE-2024-6039 is an SQL injection vulnerability.
5
Can CVE-2024-6039 be exploited remotely?
Yes, CVE-2024-6039 allows for remote exploitation.