CVE-2024-51165 Information

Description

SQL injection vulnerability in JEPAAS7.2.8 via /je/rbac/rbac/loadLoginCount in the dateVal parameter which could allow a remote user to submit a specially crafted query allowing an attacker to retrieve all the information stored in the DB.

Reference

https://abcc111.github.io/posts/CVE-2024-51165/ https://github.com/abcc111/vulns/blob/main/JEPaaS/SQL%20injection%20vulnerability%20in%20JEPaaS.md

Share on: