CVE-2024-29872
Sapplica
CVE-2024-29872 is a critical SQL injection vulnerability found in Sentrifugo 3.2. This vulnerability exists in the '/sentrifugo/index.php/empscreening/add' endpoint via the 'agencyids' parameter, potentially allowing unauthorized data extraction. An attacker could send a specially crafted query to the server to extract sensitive information.
While the CVSS score is high at 9.8, indicating severity, the SOCRadar Vulnerability Risk Score (SVRS) is 38. This suggests that, while the vulnerability is technically severe, it may not be actively exploited in the wild or heavily discussed on threat actor channels at this time. However, organizations using Sentrifugo 3.2 should still address this vulnerability to prevent potential exploitation and data breaches. The ability to extract all data from the server makes this a significant risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.