A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48458 | A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Datagear
Datagear datagear |
|
| CPEs | cpe:2.3:a:datagear:datagear:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Datagear
Datagear datagear |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-06T19:30:34.911Z
Reserved: 2024-08-06T06:46:27.536Z
Link: CVE-2024-7552
Updated: 2024-08-06T19:30:20.712Z
Status : Analyzed
Published: 2024-08-06T15:15:42.297
Modified: 2024-08-07T21:29:57.417
Link: CVE-2024-7552
No data.
OpenCVE Enrichment
No data.
EUVD