← All CVEs

CVE-2024-39309

critical · 9.8

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and 7.1.0. No known workarounds are available.

9.8
CVSS
20.2%
EPSS (exploit prob.)
97th
EPSS percentile
2024-07-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89CWE-288

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-39309