Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-7099

Опубликовано: 13 окт. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include get_knowledge_base_name, from_status_to_status, delete_files, and get_file_by_status. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:*

EPSS

Процентиль: 28%
0.00102
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.

EPSS

Процентиль: 28%
0.00102
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89