CVE-2024-29875
Sapplica
CVE-2024-29875: A critical SQL injection vulnerability exists in Sentrifugo 3.2. This flaw allows a remote attacker to inject malicious SQL queries via the 'sort_name' parameter in the /sentrifugo/index.php/default/reports/exportactiveuserrpt endpoint. Successful exploitation grants the attacker unauthorized access to extract sensitive data from the server's database. While the CVSS score is high (9.8), the SOCRadar Vulnerability Risk Score (SVRS) is 38, suggesting the real-world threat activity is currently lower than the maximum potential. However, given it's a SQL Injection flaw (CWE-89), organizations using Sentrifugo 3.2 should patch this vulnerability to prevent potential data breaches. Despite the lower SVRS, the potential impact of a successful attack remains significant. The 'In The Wild' tag indicates that exploitation has been observed, warranting prompt attention to mitigate associated risks.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.