cve/2024/CVE-2024-22108.md
2024-06-18 02:51:15 +02:00

788 B

CVE-2024-22108

Description

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value.

POC

Reference

Github

No PoCs found on GitHub currently.