Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2024-10660 โ€” AI Deep Analysis Summary

CVSS 6.3 ยท Medium

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: SQL Injection in **EsafeNet CDG v5**. ๐Ÿ“‰ **Consequences**: Attackers can manipulate database queries via the `hookId` parameter in `HookService.java`.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: **CWE-89** (SQL Injection). ๐Ÿ› **Flaw**: The file `/com/esafenet/servlet/policy/HookService.java` fails to properly sanitize the `hookId` input parameter before using it in SQL operations.โ€ฆ

Q3Who is affected? (Versions/Components)

๐Ÿข **Vendor**: **ESAFENET** (China Yisaitong). ๐Ÿ“ฆ **Product**: **CDG** (Document Security Management System). ๐Ÿ“… **Affected Version**: **v5**.โ€ฆ

Q4What can hackers do? (Privileges/Data)

๐Ÿ’ป **Capabilities**: Hackers can execute arbitrary SQL commands. ๐Ÿ”“ **Privileges**: Requires **Local Privileges** (PR:L) to exploit.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”‘ **Auth Required**: **YES**. โš ๏ธ **Threshold**: **Medium**. The CVSS vector `PR:L` means the attacker must have **Local Privileges** (authenticated access) on the system. It is NOT a remote unauthenticated exploit.โ€ฆ

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ’ฃ **Public Exploit**: **Likely Available**. ๐Ÿ“Ž **Evidence**: References include a link tagged as `exploit` (Flowus share) and third-party advisories on VulDB.โ€ฆ

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check Method**: Scan for **EsafeNet CDG v5** installations. ๐ŸŽฏ **Target URL**: Look for requests to `/com/esafenet/servlet/policy/HookService`. ๐Ÿงช **Test**: Inject SQL payloads into the `hookId` parameter.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿ› ๏ธ **Official Fix**: **Unknown/Not Explicitly Stated**. ๐Ÿ“ **Note**: The provided data does not contain a specific patch version or vendor advisory link confirming a fixed version.โ€ฆ

Q9What if no patch? (Workaround)

๐Ÿšง **Workaround**: If no patch is available, **restrict access** to the `HookService` endpoint. ๐Ÿ”’ **Network**: Block external access to the CDG management interface.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

โฐ **Urgency**: **Medium-High**. ๐Ÿ“ˆ **Reason**: Although it requires local privileges, SQL Injection is a critical flaw type. ๐Ÿ“‰ **CVSS**: The vector `AV:N/AC:L/PR:L` means it's easy to exploit if you have access.โ€ฆ