A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cyberpower powerpanel
|
|
| CPEs | cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:enterprise:windows:*:* | |
| Vendors & Products |
Cyberpower powerpanel
|
Tue, 25 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cyberpower
Cyberpower powerpanel Enterprise |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:cyberpower:powerpanel_enterprise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cyberpower
Cyberpower powerpanel Enterprise |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2025-03-25T18:10:55.407Z
Reserved: 2024-04-17T11:47:39.834Z
Link: CVE-2024-32736
Updated: 2024-08-02T02:20:35.213Z
Status : Analyzed
Published: 2024-05-14T15:37:03.870
Modified: 2025-10-23T12:14:01.773
Link: CVE-2024-32736
No data.
OpenCVE Enrichment
No data.
Weaknesses