You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The unauthorized SQL injection vulnerability in the /drag/onlDragDatasetHead/getTotalData interface was not completely fixed in 3.7.2.
This version checks the legitimacy of the field before performing the SQL query, but it can still be bypassed.
错误截图:
We tried to use the POC of CVE-2024-48307.
We can delete 'concat' to bypass.
POC
版本号:
v3.7.2
问题描述:
The unauthorized SQL injection vulnerability in the /drag/onlDragDatasetHead/getTotalData interface was not completely fixed in 3.7.2.
This version checks the legitimacy of the field before performing the SQL query, but it can still be bypassed.
错误截图:
We tried to use the POC of CVE-2024-48307.
We can delete 'concat' to bypass.
POC
友情提示:
The text was updated successfully, but these errors were encountered: