Description
Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/person/pic_show.php, in the 'person_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27541 | Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/person/pic_show.php, in the 'person_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the server and retrieve all the information stored in the DB. |
References
History
Thu, 17 Apr 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amss\+\+ Project
Amss\+\+ Project amss\+\+ |
|
| CPEs | cpe:2.3:a:amss\+\+_project:amss\+\+:4.31:*:*:*:*:*:*:* | |
| Vendors & Products |
Amss\+\+ Project
Amss\+\+ Project amss\+\+ |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-28T15:39:21.612Z
Reserved: 2024-03-18T11:08:58.611Z
Link: CVE-2024-2592
Updated: 2024-08-01T19:18:47.972Z
Status : Analyzed
Published: 2024-03-18T14:15:11.987
Modified: 2026-06-17T07:24:51.017
Link: CVE-2024-2592
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
EUVD