KEVIntel
5.3
CVSS
Medium

CVE-2024-11305

PUBLISHED

Altenergy Power Control Software status_zigbee get_status_zigbee sql injection

Exploited in the wild Remote Low complexity No user interaction
Vendor
Altenergy
Product
Power Control Software
Published
Nov 18, 2024
EPSS

Description

A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. In Altenergy Power Control Software bis 20241108 wurde eine Schwachstelle entdeckt. Sie wurde als kritisch eingestuft. Hierbei betrifft es die Funktion get_status_zigbee der Datei /index.php/display/status_zigbee. Durch die Manipulation des Arguments date mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff über das Netzwerk. Der Exploit steht zur öffentlichen Verfügung.

php nuclei_scanner

CVSS scores

CVSS v4.0 5.3 Medium

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

CVSS v3.1 6.3 Medium

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS v3.0 6.3 Medium

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS v2.0 6.5

AV:N/AC:L/Au:S/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2025-04-22 00:00:00 UTC · Source

SSVC decision points

Exploitation
poc
Automatable
No
Technical impact
partial

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) Apr 24, 2025

Scanner integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei