Metrics
Affected Vendors & Products
Fri, 13 Dec 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Cjbi
Cjbi wetech-cms |
|
CPEs | cpe:2.3:a:cjbi:wetech-cms:1.0:*:*:*:*:*:*:* cpe:2.3:a:cjbi:wetech-cms:1.1:*:*:*:*:*:*:* cpe:2.3:a:cjbi:wetech-cms:1.2:*:*:*:*:*:*:* |
|
Vendors & Products |
Cjbi
Cjbi wetech-cms |
Wed, 11 Dec 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 11 Dec 2024 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerability is the function findUser of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\UserDao.java. The manipulation of the argument searchValue/gId/rId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | cjbi wetech-cms UserDao.java findUser sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-11T19:31:04.913Z
Updated: 2024-12-11T21:17:07.403Z
Reserved: 2024-12-11T12:34:25.485Z
Link: CVE-2024-12481
Updated: 2024-12-11T21:17:04.191Z
Status : Analyzed
Published: 2024-12-12T01:40:29.260
Modified: 2024-12-13T17:11:19.967
Link: CVE-2024-12481
No data.