A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within MCUDBHelper.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cyberpower powerpanel
|
|
| CPEs | cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:enterprise:windows:*:* | |
| Vendors & Products |
Cyberpower powerpanel
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-02T02:20:35.316Z
Reserved: 2024-04-17T11:47:39.834Z
Link: CVE-2024-32737
Updated: 2024-08-02T02:20:35.316Z
Status : Analyzed
Published: 2024-05-14T15:37:04.270
Modified: 2025-10-23T12:14:21.957
Link: CVE-2024-32737
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:06:40Z
Weaknesses