CRITICAL
hongmaple octopus list sql injection
Published Jan 22, 2024
9.8
CRITICALCVSS 3.1
EPSS 0.68%
Description
A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation of the argument dataScope leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-251700.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16572 Advisory
- https://github.com/biantaibao/octopus_SQL/blob/main/report.md exploit
- https://vuldb.com/?ctiid.251700 signaturepermissions-requiredPermissions RequiredThird Party Advisory
- https://vuldb.com/?id.251700 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-16572 | Advisory | |
| https://github.com/biantaibao/octopus_SQL/blob/main/report.md | exploit | |
| https://vuldb.com/?ctiid.251700 | signaturepermissions-requiredPermissions RequiredThird Party Advisory | |
| https://vuldb.com/?id.251700 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 22, 2024
Updated May 30, 2025
Reserved Jan 22, 2024
Link CVE-2024-0784
CISA Vulnrichment
Updated May 8, 2025
ENISA EUVD
EUVD-2024-16572 Assigner VulDB
Published Jan 22, 2024
Updated May 30, 2025
Exploited since n/a
Link EUVD-2024-16572