Description
SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database.
No analysis available yet.
Remediation
Vendor Solution
The vulnerability has been fixed in the new versions.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46727 | SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database. |
References
History
Thu, 23 Oct 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codester
Codester astrotalks |
|
| CPEs | cpe:2.3:a:codester:astrotalks:2023-10-03:*:*:*:*:*:*:* | |
| Vendors & Products |
Codester
Codester astrotalks |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:18:05.379Z
Reserved: 2024-05-30T08:48:44.536Z
Link: CVE-2024-5523
Updated: 2024-08-01T21:18:05.379Z
Status : Analyzed
Published: 2024-05-31T08:15:08.870
Modified: 2025-10-23T12:27:58.420
Link: CVE-2024-5523
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD