SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-46727 | SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the 'searchString' parameter and retrieve all information stored in the database. |
Fixes
Solution
The vulnerability has been fixed in the new versions.
Workaround
No workaround given by the vendor.
References
History
Thu, 23 Oct 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Codester
Codester astrotalks |
|
CPEs | cpe:2.3:a:codester:astrotalks:2023-10-03:*:*:*:*:*:*:* | |
Vendors & Products |
Codester
Codester astrotalks |
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:18:05.379Z
Reserved: 2024-05-30T08:48:44.536Z
Link: CVE-2024-5523

Updated: 2024-08-01T21:18:05.379Z

Status : Analyzed
Published: 2024-05-31T08:15:08.870
Modified: 2025-10-23T12:27:58.420
Link: CVE-2024-5523

No data.

No data.