{ "id": "CVE-2024-24256", "sourceIdentifier": "cve@mitre.org", "published": "2024-02-15T08:15:46.410", "lastModified": "2024-02-15T14:28:31.380", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory." }, { "lang": "es", "value": "Una vulnerabilidad de inyecci\u00f3n SQL en la plataforma de integraci\u00f3n de informaci\u00f3n empresarial espacio-temporal de Yonyou v.9.0 y anteriores permite a un atacante obtener informaci\u00f3n confidencial a trav\u00e9s del par\u00e1metro gwbhAIM en saveMove.jsp en el directorio hr_position." } ], "metrics": {}, "references": [ { "url": "https://github.com/l8l1/killl.github.io/blob/main/3.md", "source": "cve@mitre.org" } ] }