CVE-2024-55159 Information

Description

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/loginLog/list.

Reference

https://github.com/SuperDu1/CVE/issues/1 https://github.com/tiger1103/gfast/blob/os-v3.2/internal/app/system/logic/sysLoginLog/sys_login_log.go#L75

Share on: