SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2024-28145

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters.

MEDIUM 5.9EPSS 0.53%

Does this matter?

Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.

Description

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
0.53% probability · 43th percentile
CISA KEV
Not listed
Weakness
CWE-89
Source
551230f0-3615-47bd-b7cc-93e92e730bbf

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.