← back
CVE-2024-4991

SQL injection vulnerability in SiAdmin

CVSS 9.8 CRITICALEPSS 0.5%CWE-89
Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
SiAdmin · SiAdmin

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →