CVE-2024-43415

CVSS V2 None CVSS V3 None
Description
An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.
Overview
  • CVE ID
  • CVE-2024-43415
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-11-12T15:45:51.312Z
  • Last Modified Date
  • 2024-11-12T15:45:51.312Z
History
Created Old Value New Value Data Type Notes
2024-11-13 13:48:34 Added to TrackCVE