CVE-2024-43415

An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.
CVSS

No CVSS.

Configurations

No configuration.

History

13 Nov 2024, 19:15

Type Values Removed Values Added
Summary An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write ?les or execute commands. An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.

12 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-12 16:15

Updated : 2024-11-13 19:15


NVD link : CVE-2024-43415

Mitre link : CVE-2024-43415


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')