CVE-2022-24861
Summary
| CVE | CVE-2022-24861 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-20 19:15:00 UTC |
| Updated | 2022-05-03 15:02:00 UTC |
| Description | Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the system. This can lead to code execution by any basic user who has access to the system. Users are advised to upgrade. There are no known workarounds to this issue. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix some security bug by vran-dev · Pull Request #103 · vran-dev/databasir · GitHub | MISC | github.com | |
| Databasir 1.01 has Remote Code Execution vulnerability. · Advisory · vran-dev/databasir · GitHub | CONFIRM | github.com | |
| fix some security bug (#103) · vran-dev/databasir@ca22a8f · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.