Vulnerability Description
SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Silverpeas | Silverpeas | 6.4.1 |
Related Weaknesses (CWE)
References
- https://gist.github.com/SubZ3r0-0x01/7150f7cbc3b7d810adb221cae3d08fc8ExploitThird Party Advisory
- https://github.com/Silverpeas/Silverpeas-Components/pull/859Issue TrackingPatch
- https://github.com/Silverpeas/Silverpeas-Core/pull/1353Issue TrackingPatch
FAQ
What is CVE-2024-48814?
CVE-2024-48814 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL Injection vulnerability in Silverpeas 6.4.1 allows a remote attacker to obtain sensitive information via the ViewType parameter of the findbywhereclause function
How severe is CVE-2024-48814?
CVE-2024-48814 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-48814?
Check the references section above for vendor advisories and patch information. Affected products include: Silverpeas Silverpeas.