High severity7.5NVD Advisory· Published Dec 10, 2024· Updated Jun 17, 2026
CVE-2024-51165
CVE-2024-51165
Description
SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- abcc111.github.io/posts/CVE-2024-51165/nvdExploitThird Party Advisory
- github.com/abcc111/vulns/blob/main/JEPaaS/SQL%20injection%20vulnerability%20in%20JEPaaS.mdnvdBroken Link
News mentions
0No linked articles in our index yet.