CVE-2024-32739

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
14/05/2024
Last modified:
23/10/2025

Description

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyberpower:powerpanel:*:*:*:*:enterprise:windows:*:* 2.8.3 (excluding)