An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-3240 | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands. | 
  Github GHSA | 
                GHSA-cxwf-qc32-375f | Decidim-Awesome has SQL injection in AdminAccountability | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Thu, 14 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Decidim International Community Environment
         Decidim International Community Environment decidim-module-decidim Awesome  | 
|
| CPEs | cpe:2.3:a:decidim_international_community_environment:decidim-module-decidim_awesome:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Decidim International Community Environment
         Decidim International Community Environment decidim-module-decidim Awesome  | 
|
| Metrics | 
        
        ssvc
         
  | 
Wed, 13 Nov 2024 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands. | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands. | 
Tue, 12 Nov 2024 16:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands. | |
| Title | Decidim-Awesome: SQL injection in AdminAccountability | |
| Weaknesses | CWE-89 | |
| References | 
         | 
        
  | 
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-14T16:31:36.386Z
Reserved: 2024-08-12T18:02:04.967Z
Link: CVE-2024-43415
Updated: 2024-11-14T16:31:30.916Z
Status : Awaiting Analysis
Published: 2024-11-12T16:15:21.800
Modified: 2024-11-13T19:15:08.580
Link: CVE-2024-43415
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD
 Github GHSA