Description
A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of the file /api/dept. The manipulation of the argument params.dataScope leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271154 is the identifier assigned to this vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47732 | A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of the file /api/dept. The manipulation of the argument params.dataScope leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-271154 is the identifier assigned to this vulnerability. |
References
History
Fri, 10 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:witmy:my-springsecurity-plus:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-08-01T21:41:04.230Z
Reserved: 2024-07-11T08:51:17.502Z
Link: CVE-2024-6681
Updated: 2024-08-01T21:41:04.230Z
Status : Analyzed
Published: 2024-07-11T17:15:17.467
Modified: 2025-10-10T15:38:25.047
Link: CVE-2024-6681
No data.
OpenCVE Enrichment
Updated: 2025-07-12T23:05:49Z
Weaknesses
EUVD