nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58309 CVE-2024-58309
HIGH
xbtitFM 4.1.18 Unauthenticated SQL Injection in shoutedit.php
Record summary
CVE-2024-58309 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
xbtitFM 4.1.18 contains an unauthenticated SQL injection vulnerability that allows remote attackers to manipulate database queries by injecting malicious SQL code through the msgid parameter. Attackers can send crafted requests to /shoutedit.php with EXTRACTVALUE functions to extract database names, user credentials, and password hashes from the underlying database.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 16, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
xbtitFMBrowse xbtitfm / xbtitFMDefault status: unaffected | CVE List | 4.1.18 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBxbtitFM 4.1.18 - Multiple VulnerabilitiesExploitDB exploitby h5kj23kj32io2kjNot analyzed1 file
References
4ExploitDB-51909exploit
https://www.exploit-db.com/exploits/51909 VulnCheck Advisory: xbtitFM 4.1.18 Unauthenticated SQL Injection in shoutedit.phpThird-party advisory
https://www.vulncheck.com/advisories/xbtitfm-unauthenticated-sql-injection-in-shouteditphp Official Vendor Homepageproduct
https://xbtitfm.eu/