CVE-2024-12245
CVE-2024-12245: Unauthenticated SQL injection vulnerability! Exploit exposes database contents. CVE-2024-12245 describes a critical security flaw found in the logout functionality, enabling unauthorized attackers to perform blind SQL injection. By using time-based techniques, attackers could potentially extract the entire database content. While the CVSS score is 0, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting a moderate risk but potential exploitability. If successful in dumping database credentials, account takeover is possible, depending on the specific database table configurations. The presence of the "In The Wild" tag increases the urgency. Immediate patching is advised to prevent unauthorized data access, even with the low SVRS. The vulnerability is categorized under CWE-89, highlighting the improper neutralization of special elements used in an SQL command.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.