← العودة للجدول
CVE-2024-24004
CVE-2024-24004 — jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHead
📅 2024-02-07
🔴 Critical 🔥 No NVD Exploit OT/ICS CVSS 9.8 🎯 EPSS 0.12%

📋 الوصف الكامل

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload to bypass jshERP's protection mechanism in `safeSqlParse` method for sql injection.

💻 الأنظمة المتأثرة

jshERP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2024-24004

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2024-24004 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←