CVE-2024-35584

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 15, 2024
Updated: Oct 16, 2024
CWE ID 89

Summary

CVE-2024-35584 is a recently disclosed SQL injection vulnerability affecting OpenSis Community Edition versions 9.1 to 8.0, and potentially older releases. This issue stems from insufficient sanitization in Ajax.php, ForWindow.php, ForExport.php, Modules.php, and functions/HackingLogFnc.php. An authenticated user can exploit this flaw by injecting SQL code into the application via the "X-Forwarded-For" header, which is directly appended to SQL INSERT statements, leading to unintended database access and potential data manipulation or extraction.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share