CVE-2024-9918

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Oct 13, 2024
Updated: Oct 19, 2024
CWE ID 89

Summary

CVE-2024-9918 is a newly disclosed critical vulnerability that impacts HuangDou UTCMS V9. The issue lies in the "RunSql" function of the file "app/modules/ut-data/admin/sql.php," which becomes susceptible to sql injection when the argument "sql" is manipulated. The vulnerability can be exploited remotely, making it a significant security concern. The exploit for this vulnerability has been made public, increasing the risk of potential attacks. Despite early notifications, the vendor has not responded to the disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share