CVE-2024-11305

MEDIUM EXPLOITED NUCLEI

Altenergy Power Control Software <20241108 - SQL Injection

Title source: llm

Description

A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (1)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/Altenergy(CVE-2024-11305).py

Nuclei Templates (1)

Altenergy Power Control Software - SQL Injection
MEDIUMby s4e-io
Shodan: http.title:"altenergy power control software"
FOFA: title="altenergy power control software"

Scores

CVSS v3 6.3
EPSS 0.4616
EPSS Percentile 97.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

VulnCheck KEV 2024-12-24
CWE
CWE-74 CWE-89
Status published
Products (1)
Altenergy/Power Control Software 20241108
Published Nov 18, 2024
Tracked Since Feb 18, 2026