CVE-2024-35548
CVE-2024-35548 reveals a SQL injection vulnerability in Mybatis Plus versions prior to 3.5.6. This flaw enables remote attackers to potentially extract sensitive database information through a Boolean blind injection technique if the application is misconfigured. The SOCRadar Vulnerability Risk Score (SVRS) is 34, indicating a moderate risk, even though the CVSS score is 5.4. This discrepancy suggests SOCRadar considers external factors like exploit availability and threat actor interest, as indicated by the 'In The Wild' tag. Although the vendor states this vulnerability requires a misconfigured application, the risk remains significant. Successful exploitation of this vulnerability could lead to unauthorized data access, impacting confidentiality and potentially integrity. Immediate review of Mybatis Plus configurations and updates to the latest version are recommended to mitigate the SQL injection vulnerability.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.