mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
708 B
708 B
CVE-2024-25168
Description
SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.
POC
Reference
- https://github.com/biantaibao/snow_SQL/blob/main/report.md
- https://github.com/biantaibao/snow_SQL/blob/main/report.md