CVE-2024-27718

HIGH NUCLEI

Smart s200 Management Platform v.S200 - SQL Injection

Title source: nuclei
STIX 2.1

Exploitation Summary

CVE-2024-27718 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component.

Nuclei Templates (1)

Smart s200 Management Platform v.S200 - SQL Injection
HIGHVERIFIEDby DhiyaneshDk
FOFA: body="Smart管理平台"

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0110
EPSS Percentile 61.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Published Mar 05, 2024
Tracked Since Feb 18, 2026