U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-1254

Change History

New CVE Received by NIST 2/06/2024 2:15:09 PM

Action Type Old Value New Value
Added CVSS V2

VulDB (AV:N/AC:L/Au:M/C:P/I:P/A:P)
Added CVSS V3.1

Added CWE

VulDB CWE-89
Added Description

A vulnerability, which was classified as critical, was found in Beijing Baichuo Smart S20 Management Platform up to 20231120. This affects an unknown part of the file /sysmanage/sysmanageajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252993 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Added Reference

VulDB https://github.com/rockersiyuan/CVE/blob/main/Smart%20S20.md [No types assigned]
Added Reference

VulDB https://vuldb.com/?ctiid.252993 [No types assigned]
Added Reference

VulDB https://vuldb.com/?id.252993 [No types assigned]