CVE-2024-22856

A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows authenticated attackers to execute unintended queries and disclose sensitive information from DB tables via crafted requests.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-04-22 12:15

Updated : 2024-07-03 01:47


NVD link : CVE-2024-22856

Mitre link : CVE-2024-22856

CVE.ORG link : CVE-2024-22856


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')