CVE-2024-32736
7.5HIGHA sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function withi
Veröffentlicht: 5/14/2024Aktualisiert: 10/23/2025
Beschreibung
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.
KI-AnalyseKI-gestützt
Betroffene Produkte
cyberpowerpowerpanel
Referenzen
- https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&fileSubType=FileReleaseNoteRelease Notes
- https://www.tenable.com/security/research/tra-2024-14Third Party Advisory
- https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&fileSubType=FileReleaseNoteRelease Notes
- https://www.tenable.com/security/research/tra-2024-14Third Party Advisory