Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-32493

Опубликовано: 29 апр. 2024
Источник: debian

Описание

An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
znunyfixed6.5.8-1package
znunyno-dsabookwormpackage

Примечания

  • https://www.znuny.org/en/advisories/zsa-2024-03

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 2 года назад

An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.

CVSS3: 8.8
nvd
почти 2 года назад

An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.

CVSS3: 8.8
github
почти 2 года назад

An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able to inject SQL in the draft form ID parameter of an AJAX request.