Vulnerability Description
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gttb | Gtb Central Console | 15.17.1-30814.ng |
Related Weaknesses (CWE)
References
- https://adepts.of0x.cc/gtbcc-pwned/ExploitThird Party Advisory
- https://x-c3ll.github.io/cves.htmlExploit
- https://adepts.of0x.cc/gtbcc-pwned/ExploitThird Party Advisory
- https://x-c3ll.github.io/cves.htmlExploit
FAQ
What is CVE-2024-22108?
CVE-2024-22108 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.p...
How severe is CVE-2024-22108?
CVE-2024-22108 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-22108?
Check the references section above for vendor advisories and patch information. Affected products include: Gttb Gtb Central Console.