Record summary

CVE-2024-4257 has a selected CVSS score of 6.3 (medium); EIP currently links 1 Nuclei template.

Description

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/deleteStudy.php. The manipulation of the argument documentUniqueId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-262149 was assigned to this vulnerability.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE List1.2.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMBlueNet Technology Clinical Browsing System 1.2.1 - Sql InjectionCVSS 6.3

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file /xds/deleteStudy.php. The manipulation of the argument documentUniqueId leads to sql injection. It is possible to initiate the attack remotely.

Impact

Authenticated attackers can execute time-based SQL injection to extract sensitive database information.

Remediation

Update BlueNet Technology Clinical Browsing System to a version later than 1.2.1 that patches the SQL injection vulnerability.

WeaknessesCWE-89
Authorss4e-io
Template tagstime-based-sqlicvecve2024sqliblunetvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
FOFA: app="LANWON-临床浏览系统"

Source: ProjectDiscovery

References

5
VDB-262149 | BlueNet Technology Clinical Browsing System deleteStudy.php sql injectionvdb entryTechnical description
https://vuldb.com/?id.262149