MEDIUM
DataGear resolveSql sql injection
Published Nov 23, 2024
5.3
MEDIUMCVSS 4.0
EPSS 0.64%
Description
A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. Upgrading to version 4.7.0 is able to address this issue. It is recommended to upgrade the affected component.
Affected products
- Vendor n/a Product DataGear Defaultunknown
Affected
- 4.0
- 4.1
- 4.10
- 4.11
- 4.12
- 4.13
- 4.14
- 4.15
- 4.16
- 4.17
- 4.18
- 4.19
- 4.2
- 4.20
- 4.21
- 4.22
- 4.23
- 4.24
- 4.25
- 4.26
- 4.27
- 4.28
- 4.29
- 4.3
- 4.30
- 4.31
- 4.32
- 4.33
- 4.34
- 4.35
- 4.36
- 4.37
- 4.38
- 4.39
- 4.4
- 4.40
- 4.41
- 4.42
- 4.43
- 4.44
- 4.45
- 4.46
- 4.47
- 4.48
- 4.49
- 4.5
- 4.50
- 4.51
- 4.52
- 4.53
- 4.54
- 4.55
- 4.56
- 4.57
- 4.58
- 4.59
- 4.6
- 4.60
- 4.7
- 4.8
- 4.9
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | DataGear | unknown | Affected
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59677 Advisory
- https://github.com/datageartech/datagear/issues/29 issue-trackingExploit
- https://vuldb.com/?ctiid.285658 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.285658 vdb-entrytechnical-descriptionThird Party Advisory
- https://vuldb.com/?submit.442943 third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59677 | Advisory | |
| https://github.com/datageartech/datagear/issues/29 | issue-trackingExploit | |
| https://vuldb.com/?ctiid.285658 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.285658 | vdb-entrytechnical-descriptionThird Party Advisory | |
| https://vuldb.com/?submit.442943 | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Nov 23, 2024
Updated Nov 26, 2024
Reserved Nov 21, 2024
Link CVE-2023-7299
CISA Vulnrichment
Updated Nov 26, 2024
Red Hat
No data
GitHub
No data