github.com
https://github.com/evilnapsis/inventio-lite CVE-2024-44541
CRITICAL
Inventio Lite 4 - SQL Injection
Record summary
CVE-2024-44541 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
inventio-liteBrowse evilnapsis / inventio-liteDefault status: unknown | CVE List | Through 4 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBInventio Lite 4 - SQL InjectionExploitDB exploitby pointedsecNot analyzed1 file
Repository PoCs
GitHubpointedsec/CVE-2024-44541Repository PoCby pointedsecStars: 0Not analyzed4 files
References
3github.com
https://github.com/pointedsec/CVE-2024-44541 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-44541