CVE-2024-29876
Sapplica
CVE-2024-29876: SQL injection vulnerability in Sentrifugo 3.2 allows remote attackers to execute arbitrary SQL queries. The vulnerability is located in the '/sentrifugo/index.php/reports/activitylogreport' via the 'sortby' parameter. This SQL injection flaw enables attackers to craft malicious queries, potentially leading to unauthorized data extraction.
Although CVE-2024-29876 has a CVSS score of 9.8, SOCRadar's Vulnerability Risk Score (SVRS) is 38. This means that based on threat intelligence gathered from various sources, the immediate risk may be lower than indicated by CVSS alone. Nonetheless, the vulnerability remains significant because successful exploitation allows attackers to compromise the database. Organizations using Sentrifugo 3.2 should apply necessary patches and mitigations to prevent potential data breaches, despite the lower SVRS, especially given the "In The Wild" tag suggests active exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.