Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-34532

May 6, 2024, 9:15 p.m.

Product(s) Impacted

Yvan Dotet PostgreSQL Query Deluxe module

  • 17.x before 17.0.0.4

Description

A SQL injection vulnerability in Yvan Dotet PostgreSQL Query Deluxe module (aka query_deluxe) 17.x before 17.0.0.4 allows a remote attacker to gain privileges via the query parameter to models/querydeluxe.py:QueryDeluxe::get_result_from_query.

Weaknesses

Date

Published: May 6, 2024, 9:15 p.m.

Last Modified: May 6, 2024, 9:15 p.m.

Status : Received

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

References

https://github.com/ cve@mitre.org