CVE-2024-27718

HIGH NUCLEI

Smart s200 Management Platform v.S200 - SQL Injection

Title source: nuclei

Description

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

Nuclei Templates (1)

Smart s200 Management Platform v.S200 - SQL Injection
HIGHVERIFIEDby DhiyaneshDk
FOFA: body="Smart管理平台"

Scores

CVSS v3 7.8
EPSS 0.0631
EPSS Percentile 91.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Published Mar 05, 2024
Tracked Since Feb 18, 2026