Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-264g-23wx-93mv

Опубликовано: 01 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially disclose sensitive information.

An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially disclose sensitive information.

EPSS

Процентиль: 38%
0.00165
Низкий

8.7 High

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
7 месяцев назад

An SQL injection vulnerability exists in the Dahua Smart Cloud Gateway Registration Management Platform via the username parameter in the /index.php/User/doLogin endpoint. The application fails to properly sanitize user input, allowing unauthenticated attackers to inject arbitrary SQL statements and potentially disclose sensitive information. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.

EPSS

Процентиль: 38%
0.00165
Низкий

8.7 High

CVSS4

Дефекты

CWE-89