Medium severity6.3NVD Advisory· Published Mar 22, 2024· Updated Jun 17, 2026
CVE-2024-25168
CVE-2024-25168
Description
SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- snow/snowdescription
- Range: =2.0.0
Patches
Vulnerability mechanics
References
1- github.com/biantaibao/snow_SQL/blob/main/report.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.