CVE-2024-8023: chillzhuang SpringBlade list sql injection
Published Aug 20, 2024
·Updated
A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
2 affected components
chillzhuang SpringBlade
Bladex Springblade<=4.1.0
Event History
Aug 20, 2024
CVE Published
via MITRE·11:31 PM
Data Sourced
via MITRE·11:31 PM
DescriptionSeverityWeakness
Aug 21, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-8023?
CVE-2024-8023 is classified as a critical vulnerability.
2
How do I fix CVE-2024-8023?
To fix CVE-2024-8023, update to the latest version of SpringBlade where the vulnerability is patched.
3
What kind of vulnerability is CVE-2024-8023?
CVE-2024-8023 is a SQL injection vulnerability.
4
Can CVE-2024-8023 be exploited remotely?
Yes, CVE-2024-8023 can be exploited remotely.
5
Which software is affected by CVE-2024-8023?
CVE-2024-8023 affects chillzhuang SpringBlade version 4.1.0.