Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-34472

Опубликовано: 06 мая 2024
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hsclabs:mailinspector:*:*:*:*:*:*:*:*
Версия от 5.2.17-3 (включая) до 5.2.19 (исключая)

EPSS

Процентиль: 84%
0.02316
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 5.9
github
почти 2 года назад

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in a POST request to /mailinspector/mliRealtimeEmails.php does not properly sanitize input, allowing an authenticated attacker to execute arbitrary SQL commands, leading to the potential disclosure of the entire application database.

EPSS

Процентиль: 84%
0.02316
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-89