CVE-2024-11060

MEDIUM

Jinher Network Collaborative Management Platform 1.0 - SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability classified as critical has been found in Jinher Network Collaborative Management Platform 金和数字化智能办公平台 1.0. Affected is an unknown function of the file /C6/JHSoft.Web.AcceptAip/AcceptShow.aspx/. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.283806
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.283806
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.440344

Scores

CVSS v3 6.3
EPSS 0.0031
EPSS Percentile 22.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
Jinher Network/Collaborative Management Platform 金和数字化智能办公平台 1.0
Published Nov 11, 2024
Tracked Since Feb 18, 2026