github.com
https://github.com/advisories/GHSA-75jf-52jg-qqh4 CVE-2024-32231
MEDIUMNuclei
SQL injection in github.com/stashapp/stash
Record summary
CVE-2024-32231 has a selected CVSS score of 6.3 (medium); EIP currently links 1 Nuclei template.
Description
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
github.com/stashapp/stashBrowse Go / github.com/stashapp/stash | GitHub Advisory | Before 0.26.0 · Fixed in 0.26.0 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALStash < 0.26.0 - SQL Injection
Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.
Impact
Attackers can execute arbitrary SQL queries via the sort parameter, potentially extracting sensitive database information.
Remediation
Update Stash to version 0.26.0 or later.
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024stashsqlivuln
Shodan: html:"<title>Stash</title>"
https://github.com/stashapp https://github.com/stashapp/stash https://github.com/stashapp/stash/pull/4865 https://github.com/advisories/GHSA-75jf-52jg-qqh4 https://nvd.nist.gov/vuln/detail/CVE-2024-32231
Source: ProjectDiscovery
References
7github.com
https://github.com/stashapp github.com
https://github.com/stashapp/stash github.com
https://github.com/stashapp/stash/commit/89553864f5fa92beaa37a12e489064b1358d9880 github.com
https://github.com/stashapp/stash/pull/4865 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-32231 pkg.go.dev
https://pkg.go.dev/vuln/GO-2024-3070