Record summary

CVE-2024-13979 has a selected CVSS score of 9.3 (critical); EIP currently links 1 Nuclei template.

Description

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-04-14 UTC.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 14, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unknown

CVE List*affected

Nuclei templates

1
ProjectDiscoveryCRITICALSt. Joe ERP system - SQL InjectionCVSS 9.8

A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database.

Impact

Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined.

Remediation

Update to the latest version of St. Joe ERP system.

WeaknessesCWE-89
AuthorsDhiyaneshDK
Template tagscvecve2024erpsqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:st._joe_erp_system_project:st._joe_erp_system:-:*:*:*:*:*:*:*
FOFA: 圣乔ERP系统

Source: ProjectDiscovery

References

5