CVE-2024-51165 Information
Dec 11, 2024
cve
Description
SQL injection vulnerability in JEPAAS7.2.8 via /je/rbac/rbac/loadLoginCount in the dateVal parameter which could allow a remote user to submit a specially crafted query allowing an attacker to retrieve all the information stored in the DB.
Reference
https://abcc111.github.io/posts/CVE-2024-51165/ https://github.com/abcc111/vulns/blob/main/JEPaaS/SQL%20injection%20vulnerability%20in%20JEPaaS.md
Share on: