CVE-2024-7552
MEDIUMDescription
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.
Is your site exposed to CVE-2024-7552?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| datagear | datagear |
References
Frequently Asked Questions
What is CVE-2024-7552? +
How severe is CVE-2024-7552? +
What products are affected by CVE-2024-7552? +
How do I check if I'm vulnerable to CVE-2024-7552? +
Related Vulnerabilities
An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.
ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications …
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when …
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but …
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the …
Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …