CVE-2024-43415
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
12/11/2024
Last modified:
13/11/2024
Description
An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.
Impact
Base Score 3.x
9.00
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://github.com/decidim-ice/decidim-module-decidim_awesome/commit/84374037d34a3ac80dc18406834169c65869f11b
- https://github.com/decidim-ice/decidim-module-decidim_awesome/security/advisories/GHSA-cxwf-qc32-375f
- https://pentest.ait.ac.at/security-advisory/decidim-awesome-sql-injection-in-adminaccountability



