Record summary

CVE-2024-27718 has a selected CVSS score of 7.8 (high); EIP currently links 1 Nuclei template.

Description

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 27, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListS200affected

Nuclei templates

1
ProjectDiscoveryHIGHSmart s200 Management Platform v.S200 - SQL Injection

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

Impact

Authenticated attackers can extract sensitive database information via SQL injection in the importexport.php component.

Remediation

Update Smart s200 Management Platform to a version that addresses CVE-2024-27718.

AuthorsDhiyaneshDk
Template tagscvecve2024smart-s45fsqlivuln
FOFA: body="Smart管理平台"

Source: ProjectDiscovery

References

2