CVE-2024-32736
7.5HIGHA sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function withi
Publicado: 5/14/2024Atualizado: 10/23/2025
Descrição
A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within MCUDBHelper.
Análise IADesenvolvido por IA
Produtos Afetados
cyberpowerpowerpanel
Referências
- https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&fileSubType=FileReleaseNoteRelease Notes
- https://www.tenable.com/security/research/tra-2024-14Third Party Advisory
- https://www.cyberpower.com/global/en/File/GetFileSampleByType?fileId=SU-18070002-07&fileSubType=FileReleaseNoteRelease Notes
- https://www.tenable.com/security/research/tra-2024-14Third Party Advisory