CVE-2024-7099

CVSS V2 None CVSS V3 None
Description
netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.
Overview
  • CVE ID
  • CVE-2024-7099
  • Assigner
  • @huntr_ai
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-13T21:09:53.816Z
  • Last Modified Date
  • 2024-10-13T21:09:53.816Z
History
Created Old Value New Value Data Type Notes
2024-10-14 13:07:03 Added to TrackCVE