Skip to content

Instantly share code, notes, and snippets.

@nscan9
Last active January 9, 2025 19:27
Show Gist options
  • Select an option

  • Save nscan9/a31982c90ab40a8e00373bf15efbf52a to your computer and use it in GitHub Desktop.

Select an option

Save nscan9/a31982c90ab40a8e00373bf15efbf52a to your computer and use it in GitHub Desktop.
[CVE ID]
CVE-2024-54761
[Product]
BigAnt Office Messenger
[Version]
5.6.06
[Vulnerability Type]
RCE via SQL Injection
[Description]
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the
'dev_code' parameter. While installing the app, stack queries are configured as open in SQL and thanks to this we can obtain RCE.
Vulnerability found latest version. Vulnerability not tested in down versions.
[Reference]
https://github.com/nscan9/CVE-2024-54761-BigAnt-Office-Messenger-5.6.06-RCE-via-SQL-Injection
https://www.bigantsoft.com/
--------------------------------------
PoC: https://github.com/nscan9/CVE-2024-54761-BigAnt-Office-Messenger-5.6.06-RCE-via-SQL-Injection
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment