Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48082 | netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2. |
Wed, 30 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qanything
Qanything qanything |
|
| CPEs | cpe:2.3:a:qanything:qanything:1.4.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Qanything
Qanything qanything |
Tue, 15 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netease
Netease qanything |
|
| CPEs | cpe:2.3:a:netease:qanything:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netease
Netease qanything |
|
| Metrics |
ssvc
|
Sun, 13 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and `get_file_by_status`. An attacker can exploit this vulnerability to execute arbitrary SQL queries, potentially stealing information from the database. The issue is fixed in version 1.4.2. | |
| Title | SQL Injection in netease-youdao/qanything | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-10-15T14:56:00.675Z
Reserved: 2024-07-25T09:33:45.994Z
Link: CVE-2024-7099
Updated: 2024-10-15T14:55:48.911Z
Status : Analyzed
Published: 2024-10-13T21:15:10.957
Modified: 2025-07-30T19:44:27.253
Link: CVE-2024-7099
No data.
OpenCVE Enrichment
No data.
EUVD