CVE-2024-34532
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
06/05/2024
Last modified:
03/07/2024
Description
A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



