CVE-2024-27718
Smart s200 Management Platform v.S200 - SQL Injection
Record summary
CVE-2024-27718 has a selected CVSS score of 7.8 (high); EIP currently links 1 Nuclei template.
Description
SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 27, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
management_platformBrowse byzronetwork / management_platformDefault status: unknown | CVE List | S200 | affected |
Nuclei templates
1ProjectDiscoveryHIGHSmart s200 Management Platform v.S200 - SQL Injection
SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.
Impact
Authenticated attackers can extract sensitive database information via SQL injection in the importexport.php component.
Remediation
Update Smart s200 Management Platform to a version that addresses CVE-2024-27718.
Source: ProjectDiscovery