Record summary

CVE-2024-32231 has a selected CVSS score of 6.3 (medium); EIP currently links 1 Nuclei template.

Description

Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 16, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

github.com/stashapp/stash

Browse Go / github.com/stashapp/stash
GitHub AdvisoryBefore 0.26.0 · Fixed in 0.26.0affected

Nuclei templates

1
ProjectDiscoveryCRITICALStash < 0.26.0 - SQL Injection

Stash up to v0.25.1 was discovered to contain a SQL injection vulnerability via the sort parameter.

Impact

Attackers can execute arbitrary SQL queries via the sort parameter, potentially extracting sensitive database information.

Remediation

Update Stash to version 0.26.0 or later.

Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024stashsqlivuln
Shodan: html:"<title>Stash</title>"

Source: ProjectDiscovery

References

7