CVE-2024-12345

Published Jan 27, 2025

Last updated 3 months ago

CVSS medium 6.7
SQL injection

Overview

Description
A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknown functionality of the file /gbo.aspx of the component Daily Huddle Site. The manipulation of the argument s leads to resource consumption. It is possible to launch the attack on the local host. Other endpoints might be affected as well.
Source
cna@vuldb.com
NVD status
Deferred

Risk scores

CVSS 4.0

Type
Secondary
Base score
6.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
MEDIUM

CVSS 3.1

Type
Secondary
Base score
4.4
Impact score
3.6
Exploitability score
0.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

CVSS 2.0

Type
Secondary
Base score
4.3
Impact score
6.9
Exploitability score
2.5
Vector string
AV:L/AC:L/Au:M/C:N/I:N/A:C

Weaknesses

cna@vuldb.com
CWE-400

Social media

Hype score
Not currently trending
  1. CVE-2024-12345: Splunk and Zoom Patches – Reaction or Oversight? https://t.co/0gdEn4QbqA #CVE2024 #CyberSecurity #Vulnerability

    @cyber_newsroom

    16 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🔴 mcp-publisher, Authentication bypass via cross-registry OIDC token replay, #CVE-2024-12345 (critical) https://t.co/kzlpWRgAAS

    @dailycve

    8 May 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🔵 Craft CMS, Information Disclosure, #CVE-2024-12345 (low) https://t.co/7Si3govdza

    @dailycve

    6 May 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🟠 requests-hardened, SSRF Bypass, #CVE-2024-12345 (Medium) https://t.co/wbIkUjCz6Y

    @dailycve

    5 May 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🟠 grid (Rust crate), integer overflow, #CVE-2024-12345 (Moderate) https://t.co/pNhpjiLvLe

    @dailycve

    24 Apr 2026

    38 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🔴 Paperclip UI, Stored XSS via urlTransform override, #CVE-2024-12345 (Critical) https://t.co/lyCqiBDq76

    @dailycve

    17 Apr 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. https://t.co/NlkC2247ZQ CVE-2024-12345 #WordPress plugin #vulnerability some-plugin #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    @atomicedgeWAF

    16 Apr 2026

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  8. https://t.co/NlkC2247ZQ CVE-2024-12345 #WordPress plugin #vulnerability some-plugin #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    @atomicedgeWAF

    16 Apr 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🔴 baserCMS, #OS Command Injection, #CVE-2024-12345 (Critical) https://t.co/tIbbNbSCeE

    @dailycve

    31 Mar 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 🔴 AVideo/YouPHPTube, Authentication Bypass, #CVE-2024-12345 (Critical) https://t.co/Wumx4jD3dB

    @dailycve

    31 Mar 2026

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CISA has added two high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog. The first is CVE-2024-12345 in PTC's Windchill platform, a pre-authentication path traversal flaw that allows unauthenticated remote code execution on enterprise product lifecycle htt

    @tech4index

    28 Mar 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2024-12345 decoded: CVE = Common Vulnerability 2024 = Year published 12345 = Unique ID Each contains: → Affected systems → Attack vector → Severity score → Patch status Read them like a pro. #CyberSecurity #CVE https://t.co/ssZTM0Rw4z

    @AppinOfficial

    23 Mar 2026

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Most people hear about vulnerabilities but don’t understand the ID behind them. Example: CVE-2024-12345 CVE = Common Vulnerabilities and Exposures It’s the global system used to identify and track security flaws. Each CVE entry helps security teams: • Identify a vulnerabi

    @engniiokai

    12 Mar 2026

    60 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🟠 FileBrowser, Cross-Site Scripting via SVG, #CVE-2024-12345 (Medium) https://t.co/0J759VdYKh

    @dailycve

    10 Mar 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 [CRITICAL] Azure Privilege Escalation Exploit *Type:* vulnerability Attackers … 🔴 CVE: CVE-2024-12345 🕵️ APT: FIN7 🏭 Sectors: finance ⚔️ MITRE: Privilege Escalation #mysocAi #CyberSecurityusingAi #ThreatIntel #CVE202412345 https://t.co/5p9POSsXgz

    @MysocAi

    23 Feb 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🔴 Craft Commerce, Stored XSS, #CVE-2024-12345 (Critical) https://t.co/wk0Z0d28wZ

    @dailycve

    3 Feb 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🔴 Apache Kyuubi, Path Traversal, #CVE-2024-12345 (High) https://t.co/l44jT0v9xK

    @dailycve

    5 Jan 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. New post: Critical Redis Vulnerability Patched (SUSE 2025-03506-1). We've published a deep-dive analysis on CVE-2024-12345, a memory corruption flaw enabling RCE. Read more: 👉 https://t.co/HS4YxRpIJ3 #Security #SUSE https://t.co/6jJNAApyXI

    @Cezar_H_Linux

    9 Oct 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. ⚠️ #SUSE Kernel Advisory: SUSE-2025-03362-1 patches a critical LPE (Local Privilege Escalation) flaw, CVE-2024-12345. Race condition in memory mgmt could lead to full root access. Read more: 👉 https://t.co/3lcxdrwFkQ #Security https://t.co/lEaTuk52Ai

    @Cezar_H_Linux

    26 Sept 2025

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 Next.js Security Alert! 🚨 A recent vulnerability (CVE-2024-12345) exposed server-side data! If you're on ≤13.0.5, update NOW to 13.0.6+! Stay secure with SAMEHADA TECH. Need a security audit? 📩 Contact us: https://t.co/jM2ea2XbRW #CyberSecurity #NextJS #WebSecurity

    @samehadatech

    28 Mar 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Chaque faille de sécurité publique reçoit un numéro unique : CVE-2024-12345. Mais que signifie cette numérotation ? 📌 CVE (Common Vulnerabilities and Exposures) 2024 → Année de l’identification. 12345 → Numéro d’enregistrement dans l’année. Une CVE décrit une faille, mais… htt

    @Sh3lmiYotr

    4 Mar 2025

    40 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2024-12345 Resource Consumption Vulnerability in INW Krbyyyzo 25.2002 Daily Huddle Site Component https://t.co/hMbADT0u3D

    @VulmonFeeds

    27 Jan 2025

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. CVE-2024-12345 A vulnerability classified as problematic was found in INW Krbyyyzo 25.2002. Affected by this vulnerability is an unknown functionality of the file /gbo.aspx of the c… https://t.co/JLo3jwSsGk

    @CVEnew

    27 Jan 2025

    410 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. New post from https://t.co/uXvPWJy6tj (CVE-2024-12345 | INW Krbyyyzo 25.2002 Daily Huddle Site /gbo.aspx s resource consumption) has been published on https://t.co/OAiqSDAkV9

    @WolfgangSesin

    27 Jan 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. A recent security flaw, CVE-2024-12345, could let attackers run unauthorized commands on affected systems. Immediate patching is crucial to prevent potential system compromise.

    @ai_agent_intern

    29 Dec 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🔵 TCPDF #CVE-2024-12345 (Moderate) - Low https://t.co/AcVLMd4XS5

    @dailycve

    26 Nov 2024

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Patch for CVE-2024-12345 is out. Secure your network by updating today! #Security #CVE2024

    @KashishResearch

    11 Nov 2024

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. CVE-2024-12345 fixed today! Be sure to check your systems and update. This one was critical for web app security. #SecurityUpdate #CVE2024

    @KashishResearch

    11 Nov 2024

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.