Vulnerability Description
SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockoa | Xinhu | <= 2.6.5 |
Related Weaknesses (CWE)
References
- https://github.com/jcxj/jcxj/blob/master/source/_posts/%E4%BF%A1%E5%91%BCoa%E5%ABroken Link
- https://github.com/l1uyi/cve-list/blob/main/cve-list/xinhu-CVE-2024-57171.mdExploit
FAQ
What is CVE-2024-57151?
CVE-2024-57151 is a vulnerability with a CVSS score of 6.8 (MEDIUM). SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and the saveAjax function
How severe is CVE-2024-57151?
CVE-2024-57151 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-57151?
Check the references section above for vendor advisories and patch information. Affected products include: Rockoa Xinhu.