CVE-2024-13979
CRITICAL EXPLOITED NUCLEISt. Joe Erp System - SQL Injection
Title source: ruleDescription
A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input before incorporating it into SQL queries, enabling direct manipulation of the backend database. Successful exploitation may result in unauthorized data access, modification of records, or limited disruption of service. An affected version range is undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-04-14 UTC.
Nuclei Templates (1)
St. Joe ERP system - SQL Injection
CRITICALby DhiyaneshDK
FOFA:
圣乔ERP系统
Scores
CVSS v3
9.8
EPSS
0.0901
EPSS Percentile
92.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-04-14
CWE
CWE-89
Status
published
Products (1)
st._joe_erp_system_project/st._joe_erp_system
Published
Aug 27, 2025
Tracked Since
Feb 18, 2026