Vulnerability Description
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mindskip | Xzs-Mysql | 3.8 |
Related Weaknesses (CWE)
References
- https://github.com/menghaining/PoC/blob/main/xzs-mysql/xzs-mysql%20--%20PoC.mdExploitThird Party Advisory
- https://github.com/menghaining/PoC/blob/main/xzs-mysql/xzs-mysql%20--%20PoC.mdExploitThird Party Advisory
FAQ
What is CVE-2024-29401?
CVE-2024-29401 is a vulnerability with a CVSS score of 9.8 (CRITICAL). xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
How severe is CVE-2024-29401?
CVE-2024-29401 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-29401?
Check the references section above for vendor advisories and patch information. Affected products include: Mindskip Xzs-Mysql.