CVE-2023-24163 describes a critical SQL Injection vulnerability in Dromara hutool versions prior to 5.8.21, allowing attackers to execute arbitrary code through the aviator template engine. With a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV, Hot List) has been identified, and community discussion is minimal, its high FAUCET Risk Score of 79/100 indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.8.21CPE matchmatch criteria | cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.