CVE-2024-7099

critical

Description

netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2.

References

https://huntr.com/bounties/bc98983e-06cc-4a4b-be01-67e5010cb2c1

https://github.com/netease-youdao/qanything/commit/a87354f09d93e95350fb45eb343dc75454387554

Details

Source: Mitre, NVD

Published: 2024-10-13

Updated: 2024-10-15

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical