CVE-2024-11305
MEDIUM EXPLOITED NUCLEIAltenergy Power Control Software <20241108 - SQL Injection
Title source: llmDescription
A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Exploits (1)
github
WORKING POC
40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/Altenergy(CVE-2024-11305).py
Nuclei Templates (1)
Altenergy Power Control Software - SQL Injection
MEDIUMby s4e-io
Shodan:
http.title:"altenergy power control software"
FOFA:
title="altenergy power control software"
Scores
CVSS v3
6.3
EPSS
0.4616
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
VulnCheck KEV
2024-12-24
CWE
CWE-74
CWE-89
Status
published
Products (1)
Altenergy/Power Control Software
20241108
Published
Nov 18, 2024
Tracked Since
Feb 18, 2026