Record summary

CVE-2024-44349 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 8, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 4.7.34affected

Proofs of concept

1

Repository PoCs

GitHubAndreaF17/PoC-CVE-2024-44349Repository PoCby AndreaF17Stars: 1Not analyzed5 files

13.8 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALAnteeoWMS < v4.7.34 - SQL InjectionCVSS 9.8

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

Impact

Unauthenticated attackers can execute arbitrary SQL commands via the username parameter, potentially extracting sensitive database information.

Remediation

Update AnteeoWMS to version 4.7.34 or later.

WeaknessesCWE-89
Authorsiamnoooob, rootxharsh, pdresearch
Template tagscvecve2024sqlianteeowmsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: html:"ANTEEO"

Source: ProjectDiscovery

References

4