SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function
References
Configurations
History
01 Apr 2025, 20:37
Type | Values Removed | Values Added |
---|---|---|
First Time |
Rockoa
Rockoa xinhu |
|
References | () https://github.com/jcxj/jcxj/blob/master/source/_posts/%E4%BF%A1%E5%91%BCoa%E5%AE%A1%E8%AE%A1.md - Broken Link | |
References | () https://github.com/l1uyi/cve-list/blob/main/cve-list/xinhu-CVE-2024-57171.md - Exploit | |
CPE | cpe:2.3:a:rockoa:xinhu:*:*:*:*:*:*:*:* |
31 Mar 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Mar 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.8 |
CWE | CWE-89 |
18 Mar 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-18 21:15
Updated : 2025-04-01 20:37
NVD link : CVE-2024-57151
Mitre link : CVE-2024-57151
CVE.ORG link : CVE-2024-57151
JSON object : View
Products Affected
rockoa
- xinhu
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')