CVE-2024-43415
EUVD-2024-324012.11.2024, 16:15
An improper neutralization of special elements used in an SQL command in the papertrail/version- model of the decidim_awesome-module <= v0.11.1 (> 0.9.0) allows an authenticated admin user to manipulate sql queries to disclose information, read and write files or execute commands.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| decidim_international_community_environment | decidim-module-decidim_awesome | 𝑥 ≤ 0.9.1 | ADP |
| decidim_international_community_environment | decidim-module-decidim_awesome | 𝑥 < 0.10.3 | ADP |
| decidim_international_community_environment | decidim-module-decidim_awesome | 𝑥 ≤ 0.11.0 | ADP |
| decidim_international_community_environment | decidim-module-decidim_awesome | 𝑥 < 0.11.2 | ADP |
References