CVE-2024-34327

MEDIUM

Sielox AnyWare <2.1.2 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-34327. PoCs published by 0xsu3ks.

AI-analyzed exploit summary This repository contains a functional Python script that checks for a time-based blind SQL injection vulnerability (CVE-2024-34327) in Sielox AnyWare 2.1.2 by sending a crafted POST request to the `/auth/password-reset-token.php` endpoint and measuring the response delay.

Description

Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.

Exploits (1)

nomisec WORKING POC
by 0xsu3ks · poc
https://github.com/0xsu3ks/CVE-2024-34327

This repository contains a functional Python script that checks for a time-based blind SQL injection vulnerability (CVE-2024-34327) in Sielox AnyWare 2.1.2 by sending a crafted POST request to the `/auth/password-reset-token.php` endpoint and measuring the response delay.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Sielox AnyWare 2.1.2
No auth needed
Prerequisites: Python 3.x · requests library · target URL
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory
https://github.com/0xsu3ks/CVE-2024-34327

Scores

CVSS v3 6.5
EPSS 0.0029
EPSS Percentile 20.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
sielox/anyware 2.1.2
Published Jul 31, 2025
Tracked Since Feb 18, 2026