Metrics
Affected Vendors & Products
Thu, 29 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dingfanzu
Dingfanzu cms |
|
CPEs | cpe:2.3:a:dingfanzu:cms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dingfanzu
Dingfanzu cms |
|
Metrics |
ssvc
|
Thu, 29 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. This affects an unknown part of the file /ajax/getBasicInfo.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | dingfanzu CMS getBasicInfo.php sql injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-08-29T14:31:04.023Z
Updated: 2024-08-29T15:45:20.745Z
Reserved: 2024-08-29T07:26:23.391Z
Link: CVE-2024-8303
Updated: 2024-08-29T15:45:14.616Z
Status : Awaiting Analysis
Published: 2024-08-29T15:15:34.783
Modified: 2024-08-30T13:00:05.390
Link: CVE-2024-8303
No data.