netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.
Metrics
Affected Vendors & Products
References
History
Tue, 15 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Netease
Netease qanything |
|
CPEs | cpe:2.3:a:netease:qanything:*:*:*:*:*:*:*:* | |
Vendors & Products |
Netease
Netease qanything |
|
Metrics |
ssvc
|
Sun, 13 Oct 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2. | |
Title | SQL Injection in netease-youdao/qanything | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_0
|
MITRE
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-10-13T21:09:53.816Z
Updated: 2024-10-15T14:56:00.675Z
Reserved: 2024-07-25T09:33:45.994Z
Link: CVE-2024-7099
Vulnrichment
Updated: 2024-10-15T14:55:48.911Z
NVD
Status : Awaiting Analysis
Published: 2024-10-13T21:15:10.957
Modified: 2024-10-15T12:57:46.880
Link: CVE-2024-7099
Redhat
No data.