CVE-2022-24861

Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the system. This can lead to code execution by any basic user who has access to the system. Users are advised to upgrade. There are no known workarounds to this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:databasir:databasir:1.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 06:51

Type Values Removed Values Added
References () https://github.com/vran-dev/databasir/commit/ca22a8fef7a31c0235b0b2951260a7819b89993b - Patch, Third Party Advisory () https://github.com/vran-dev/databasir/commit/ca22a8fef7a31c0235b0b2951260a7819b89993b - Patch, Third Party Advisory
References () https://github.com/vran-dev/databasir/pull/103 - Patch, Third Party Advisory () https://github.com/vran-dev/databasir/pull/103 - Patch, Third Party Advisory
References () https://github.com/vran-dev/databasir/security/advisories/GHSA-5r2v-wcwh-7xmp - Exploit, Third Party Advisory () https://github.com/vran-dev/databasir/security/advisories/GHSA-5r2v-wcwh-7xmp - Exploit, Third Party Advisory
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.5
v3 : 9.9

Information

Published : 2022-04-20 19:15

Updated : 2024-11-21 06:51


NVD link : CVE-2022-24861

Mitre link : CVE-2022-24861

CVE.ORG link : CVE-2022-24861


JSON object : View

Products Affected

databasir

  • databasir
CWE
CWE-20

Improper Input Validation