cve/2024/CVE-2024-43406.md
2024-08-27 19:05:50 +00:00

921 B

CVE-2024-43406

Description

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.

POC

Reference

Github

No PoCs found on GitHub currently.