CVE-2024-39250
CRITICALNuclei
EfroTech Timetrax v8.3 - Sql Injection
Record summary
CVE-2024-39250 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
timetraxBrowse efrotech / timetraxDefault status: unknown | CVE List | 8.3 | affected |
Proofs of concept
1Repository PoCs
GitHubefrann/CVE-2024-39250Repository PoCby efrannStars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHEfroTech Timetrax v8.3 - Sql Injection
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.
Impact
Unauthenticated attackers can execute SQL injection attacks to extract or modify sensitive timetrax database information.
Remediation
Update EfroTech Timetrax to a version later than v8.3 that patches the SQL injection vulnerability.
Authorss4e-io, efran
Template tagscvecve2024sqlitimetraxvuln
FOFA: icon_hash="-661694518"
https://nvd.nist.gov/vuln/detail/CVE-2024-39250 https://www.tenable.com/cve/CVE-2024-39250 https://github.com/efrann/CVE-2024-39250 https://vuldb.com/?id.272268
Source: ProjectDiscovery
References
2github.com
https://github.com/efrann/CVE-2024-39250 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-39250