CVE-2024-30801
MEDIUMCloud based customer service management platform <1.0.0 - SQL Injec...
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-30801. PoCs published by WarmBrew.
AI-analyzed exploit summary The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-30801, which describes an SQL injection vulnerability in a cloud-based customer service management platform. It includes proof-of-concept code for CVE-2024-28257, demonstrating how arbitrary command execution can be achieved via task scheduling in Admin.NET.
Description
SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.
Exploits (1)
The repository contains detailed technical writeups for multiple CVEs, including CVE-2024-30801, which describes an SQL injection vulnerability in a cloud-based customer service management platform. It includes proof-of-concept code for CVE-2024-28257, demonstrating how arbitrary command execution can be achieved via task scheduling in Admin.NET.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N