CVE-2024-37843 Information

Description

Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

Reference

https://blog.smithsecurity.biz/craft-cms-unauthenticated-sqli-via-graphql

Share on: