CVE-2024-57178 Details
Description
An SQL injection vulnerability exists in Stock-Forecaster <=01-04-2020. By sending a specially crafted 'stock-symbol' parameter to the portofolio() endpoint, it is possible to trigger an SQL injection in the application. As a result, the attacker will be able the user data or manipulate the software behavior.
A SQL injection vulnerability has been identified in Stock-Forecaster versions through 01-04-2020. The issue arises in the portfolio() endpoint, where an attacker can send a specially crafted 'stock-symbol' parameter to execute arbitrary SQL commands. This exploitation could lead to unauthorized access to user data or manipulation of the application's behavior.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 10, 2025CISA-ADP
Assessed Feb 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nihal223/Stock-Forecaster | [email protected] | ProductVendor |
| https://github.com/waristea/cve-research/tree/main/CVE-2024-57178 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nihal223 Stock-Forecaster | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 10, 2025 | New CVE Received | [email protected] |
| Feb 10, 2025 | CVE Modified | CISA-ADP |
Volerion