github.com
https://github.com/lampSEC/semcms/blob/main/datacube3.md CVE-2024-31750
CRITICALNuclei
F-Logic DataCube3 req_id SQL Injection
Record summary
CVE-2024-31750 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 3, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
DataCube3Browse Field Logic / DataCube3 | VulnCheck | Version data not supplied | |
datacube3Browse f-logic / datacube3Default status: unknown | CVE List | Through 1.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHF-logic DataCube3 - SQL Injection
SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.
Impact
Attackers can execute arbitrary SQL queries, potentially extracting or modifying sensitive database information.
Remediation
Update F-logic DataCube3 to a version that patches the SQL injection vulnerability.
AuthorsDhiyaneshDK
Template tagscvecve2024datacube3sqlivkevvuln
FOFA: title="DataCube3"
https://github.com/lampSEC/semcms/blob/main/datacube3.md https://github.com/MrWQ/vulnerability-paper/blob/master/bugs/DataCube3%20getting_index_data.php%20SQL%20%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://nvd.nist.gov/vuln/detail/CVE-2024-31750 https://github.com/wjlin0/poc-doc https://github.com/wy876/POC
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-31750