CVE-2024-37699

An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.
Configurations

No configuration.

History

21 Nov 2024, 09:24

Type Values Removed Values Added
References () https://dle-news.ru/pressrelease/1909-datalife-engine-v172-press-release.html - () https://dle-news.ru/pressrelease/1909-datalife-engine-v172-press-release.html -
References () https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-17-0.19/ - () https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-17-0.19/ -
References () https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-sql-injection-sql-inekcija-17-1.19/ - () https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-sql-injection-sql-inekcija-17-1.19/ -

01 Aug 2024, 13:54

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Un problema en DataLife Engine v.17.1 y anteriores es vulnerable a la inyección SQL en dboption.

20 Jun 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-20 18:15

Updated : 2024-11-21 09:24


NVD link : CVE-2024-37699

Mitre link : CVE-2024-37699

CVE.ORG link : CVE-2024-37699


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')