Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49838 | A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 07 Oct 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Skyselang
Skyselang yyladmin |
|
| CPEs | cpe:2.3:a:skyselang:yyladmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Skyselang
Skyselang yyladmin |
Mon, 30 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yyladmin Project
Yyladmin Project yyladmin |
|
| CPEs | cpe:2.3:a:yyladmin_project:yyladmin:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Yyladmin Project
Yyladmin Project yyladmin |
|
| Metrics |
ssvc
|
Fri, 27 Sep 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical was found in skyselang yylAdmin up to 3.0. Affected by this vulnerability is the function list of the file /app/admin/controller/file/File.php of the component Backend. The manipulation of the argument is_disable leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Title | skyselang yylAdmin Backend File.php list sql injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-09-30T16:28:34.973Z
Reserved: 2024-09-27T16:20:04.076Z
Link: CVE-2024-9293
Updated: 2024-09-30T16:28:27.967Z
Status : Analyzed
Published: 2024-09-27T21:15:03.937
Modified: 2024-10-07T15:37:33.670
Link: CVE-2024-9293
No data.
OpenCVE Enrichment
No data.
EUVD