CVE-2024-22856

A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows authenticated attackers to execute unintended queries and disclose sensitive information from DB tables via crafted requests.
Configurations

No configuration.

History

22 Nov 2024, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 0.0
v2 : unknown
v3 : 5.4

21 Nov 2024, 08:56

Type Values Removed Values Added
References () https://www.4rth4s.xyz/2024/04/cve-2024-22856-authenticated-blind-sql.html - () https://www.4rth4s.xyz/2024/04/cve-2024-22856-authenticated-blind-sql.html -

03 Jul 2024, 01:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 0.0
CWE CWE-89

22 Apr 2024, 13:28

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-22 12:15

Updated : 2024-11-22 15:15


NVD link : CVE-2024-22856

Mitre link : CVE-2024-22856

CVE.ORG link : CVE-2024-22856


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')