CVE-2024-13979
St. Joe ERP System SingleRowQueryConverter SQL Injection
Record summary
CVE-2024-13979 has a selected CVSS score of 9.3 (critical); EIP currently links 1 Nuclei template.
Description
A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-04-14 UTC.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 14, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AnyShare Cloud DiskBrowse AnyShare / AnyShare Cloud Disk | VulnCheck | Version data not supplied | |
St. Joe ERP System ("圣乔ERP系统")Browse Hangzhou Shengqiao Technology Co. Ltd. / St. Joe ERP System ("圣乔ERP系统")Default status: unknown | CVE List | * | affected |
Nuclei templates
1ProjectDiscoveryCRITICALSt. Joe ERP system - SQL InjectionCVSS 9.8
A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database.
Impact
Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined.
Remediation
Update to the latest version of St. Joe ERP system.
Source: ProjectDiscovery