Vulnerability Description
netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qanything | Qanything | 1.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/netease-youdao/qanything/commit/a87354f09d93e95350fb45eb343dcPatch
- https://huntr.com/bounties/bc98983e-06cc-4a4b-be01-67e5010cb2c1ExploitThird Party Advisory
FAQ
What is CVE-2024-7099?
CVE-2024-7099 is a vulnerability with a CVSS score of 9.8 (CRITICAL). netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get...
How severe is CVE-2024-7099?
CVE-2024-7099 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-7099?
Check the references section above for vendor advisories and patch information. Affected products include: Qanything Qanything.