CVE-2024-9918
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Oct 13, 2024
Updated: Oct 19, 2024
CWE ID 89
Summary
CVE-2024-9918 is a newly disclosed critical vulnerability that impacts HuangDou UTCMS V9. The issue lies in the "RunSql" function of the file "app/modules/ut-data/admin/sql.php," which becomes susceptible to sql injection when the argument "sql" is manipulated. The vulnerability can be exploited remotely, making it a significant security concern. The exploit for this vulnerability has been made public, increasing the risk of potential attacks. Despite early notifications, the vendor has not responded to the disclosure.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.