CVE-2024-7099
CVSS V2 None
CVSS V3 None
Description
netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.
Overview
- CVE ID
- CVE-2024-7099
- Assigner
- @huntr_ai
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-13T21:09:53.816Z
- Last Modified Date
- 2024-10-13T21:09:53.816Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-7099 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-7099 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-14 13:07:03 | Added to TrackCVE |