Metrics
Affected Vendors & Products
Mon, 30 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dingfanzu
Dingfanzu cms |
|
CPEs | cpe:2.3:a:dingfanzu:cms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dingfanzu
Dingfanzu cms |
|
Metrics |
ssvc
|
Fri, 27 Sep 2024 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected by this issue is some unknown functionality of the file saveNewPwd.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. | |
Title | dingfanzu CMS saveNewPwd.php sql injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-09-27T21:31:04.050Z
Updated: 2024-09-30T16:10:41.862Z
Reserved: 2024-09-27T16:22:03.297Z
Link: CVE-2024-9294
Updated: 2024-09-30T16:10:34.866Z
Status : Awaiting Analysis
Published: 2024-09-27T22:15:13.363
Modified: 2024-09-30T12:45:57.823
Link: CVE-2024-9294
No data.