CRITICAL🇵🇱 Wersja polska

CVE-2024-5958

CVSS 9.4v4.0pub. 2024-09-18upd. 2026-06-03

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection. This issue affects Panel: before v2.3.24.

🤖 AI Analysis
How it works

The Eliz Software Panel application improperly neutralizes special characters in input data passed to SQL queries, resulting in a classic SQL Injection vulnerability (CWE-89). An attacker with basic system access (PR:L) can craft a malicious SQL query that will be executed by the database engine. The vulnerability enables attack escalation through a system command execution mechanism directly via the SQL engine (Command Line Execution through SQL Injection).

Impact

An attacker can gain full control over the system, including reading, modifying and deleting data, as well as executing arbitrary system commands on the server. Due to the high impact on confidentiality, integrity and availability of both the target system and related systems, the breach can lead to complete infrastructure takeover.

Mitigation & patch

Eliz Software Panel must be immediately updated to version v2.3.24 or later. Detailed information is available in the vendor references and USOM message number TR-24-1497.

Who is affected

Eliz Software Panel in versions earlier than v2.3.24.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Elizsoftware Panel

    APP
    Elizsoftware
    < 2.3.24
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2024-5959CRITICAL9.3PL ✓same product

Stored XSS w Eliz Software Panel — wstrzyknięcie skryptu po stronie serwera

CVE-2024-5960CRITICAL9.8PL ✓same product

Przechowywanie haseł w postaci jawnej w Elizsoftware Panel

CVE-2024-6877CRITICAL9.4PL ✓same product

Reflected XSS w Eliz Software Panel przed wersją v2.3.24