yixiaohu

2 exploits Active since Feb 2025
CVE-2024-55159 WRITEUP MEDIUM WRITEUP
GFast v2-v3.2 - SQL Injection via SortName Parameter
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.
CVSS 4.2
CVE-2024-55160 WRITEUP CRITICAL WRITEUP
GFast 2-3.2 - SQL Injection via OrderBy Parameter
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.
CVSS 9.8