Description
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/index.php, in the 'username' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27535 | Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/index.php, in the 'username' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB. |
References
History
Thu, 10 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amssplus
Amssplus amss Plus |
|
| CPEs | cpe:2.3:a:amssplus:amss_plus:4.31:*:*:*:*:*:*:* | |
| Vendors & Products |
Amssplus
Amssplus amss Plus |
|
| Metrics |
ssvc
|
Mon, 24 Mar 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amss\+\+ Project
Amss\+\+ Project amss\+\+ |
|
| CPEs | cpe:2.3:a:amss\+\+_project:amss\+\+:4.31:*:*:*:*:*:*:* | |
| Vendors & Products |
Amss\+\+ Project
Amss\+\+ Project amss\+\+ |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-10T20:24:43.888Z
Reserved: 2024-03-18T11:08:53.485Z
Link: CVE-2024-2586
Updated: 2024-08-01T19:18:47.958Z
Status : Analyzed
Published: 2024-03-18T14:15:10.540
Modified: 2025-04-11T14:47:01.320
Link: CVE-2024-2586
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD