CVE-2024-44349
AnteeoWMS < v4.7.34 - SQL Injection
Record summary
CVE-2024-44349 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
anteeowmsBrowse anteeowms / anteeowmsDefault status: unknown | CVE List | Before 4.7.34 | affected |
Proofs of concept
1Repository PoCs
GitHubAndreaF17/PoC-CVE-2024-44349Repository PoCby AndreaF17Stars: 1Not analyzed5 files
Nuclei templates
1ProjectDiscoveryCRITICALAnteeoWMS < v4.7.34 - SQL InjectionCVSS 9.8
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.
Impact
Unauthenticated attackers can execute arbitrary SQL commands via the username parameter, potentially extracting sensitive database information.
Remediation
Update AnteeoWMS to version 4.7.34 or later.
Source: ProjectDiscovery