CVE-2024-32736
7.5HIGHA sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function withi
Publicado: 5/14/2024Actualizado: 10/23/2025
Descripción
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.
Análisis IAImpulsado por IA
Productos Afectados
cyberpowerpowerpanel
Referencias
- https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&fileSubType=FileReleaseNoteRelease Notes
- https://www.tenable.com/security/research/tra-2024-14Third Party Advisory
- https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&fileSubType=FileReleaseNoteRelease Notes
- https://www.tenable.com/security/research/tra-2024-14Third Party Advisory