CVE-2024-6679 | witmy my-springsecurity-plus up to 2024-07-04 /api/role params.dataScope sql injection (Duplicate CVE-2024-40542 / IAAHCR)
A vulnerability classified as critical has been found in witmy my-springsecurity-plus up to 2024-07-04. Affected by this issue is some unknown functionality of the file /api/role. The manipulation of the argument params.dataScope leads to sql injection.
This vulnerability is documented as CVE-2024-6679. The attack can be initiated remotely. Additionally, an exploit exists.
Our investigation indicates that a second CVE-2024-40542 was assigned to this entry.