Back to overview

CVE-2022-24861

CRITICAL Exploitation: PoC
9.9
CVSS 3.1
Description
Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has remote code execution vulnerability. JDBC drivers are not validated prior to use and may be provided by users of the system. This can lead to code execution by any basic user who has access to the system. Users are advised to upgrade. There are no known workarounds to this issue.

Metadata

CVE ID
CVE-2022-24861
State
PUBLISHED
Assigner
GitHub_M
Reserved
2022-02-10 00:00 UTC
Published
2022-04-20 18:15 UTC
Last updated
2025-04-22 18:14 UTC
Primary CWE
CWE-20
CWE-20: Improper Input Validation
Vendor / Product
vran-dev / databasir
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
vran-dev databasir < 1.0.2
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20: Improper Input Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview