CVE-2024-58307

Source
https://cve.org/CVERecord?id=CVE-2024-58307
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58307.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58307
Published
2025-12-11T22:15:52.173Z
Modified
2026-03-15T14:13:08.038258Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

CSZCMS 1.3.0 contains an authenticated SQL injection vulnerability in the members view functionality that allows authenticated attackers to manipulate database queries. Attackers can inject malicious SQL code through the view parameter to potentially execute time-based blind SQL injection attacks and extract database information.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.3.0"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "the"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58307.json"