CVE-2024-3769920.06.2024, 18:15An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.SQL InjectionEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST9.8 CRITICALNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HmitreCNA------CISA-ADPADP9.8 CRITICALNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 33%Common Weakness EnumerationCWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.Referenceshttps://dle-news.ru/pressrelease/1909-datalife-engine-v172-press-release.htmlhttps://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-17-0.19/https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-sql-injection-sql-inekcija-17-1.19/https://dle-news.ru/pressrelease/1909-datalife-engine-v172-press-release.htmlhttps://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-17-0.19/https://exploit.az/threads/datalife-engine-dle-sql-inyeksiyasi-sql-injection-sql-inekcija-17-1.19/