S4E just found a medium other files scanner
medium·Product Based Web Vulnerabilities·Updated Dec 10, 2024

CVE-2024-11305 Scanner

CVE-2024-11305 Scanner - SQL Injection vulnerability in Altenergy Power Control Software

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-11305
5.3
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. The manipulation of the argument date leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Power Control Softwareby Altenergy
20241108
power_control_softwareby altenergy
0
Updated Aug 22, 2026View on NVD →
Detail

The Altenergy Power Control Software is designed to manage and monitor energy systems in residential and commercial environments. It is primarily used by energy solution providers and system integrators for its ability to optimize power distribution and monitor performance remotely. Its applications span across diverse industries, including renewable energy management and building automation.

This scanner detects a SQL Injection vulnerability in the Altenergy Power Control Software. This vulnerability stems from insufficient input validation in the `date` parameter of the `get_status_zigbee` function in `/index.php/display/status_zigbee`. Exploiting this issue allows attackers to manipulate SQL queries by injecting crafted payloads.

The vulnerability resides in the lack of sanitization and validation for the `date` parameter. An attacker can submit malicious SQL commands that execute arbitrary database queries, leading to potential data leakage or alteration. The vulnerable endpoint `/index.php/display/status_zigbee` is exposed to remote exploitation without requiring local access or elevated privileges.

If successfully exploited, this vulnerability could allow attackers to compromise sensitive data, modify records, or disrupt system operations. It may also pave the way for further attacks against the affected system, causing significant security and operational risks for users of the software.

REFERENCES

Solution Advice
  • Validate and sanitize all user inputs before processing them in SQL queries.
  • Use parameterized queries or prepared statements to prevent SQL injection attacks.
  • Regularly update software to patch known vulnerabilities.
  • Conduct security assessments to identify and mitigate risks in web applications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-11305 Scanner - SQL Injection vulnerability in Altenergy Power Control Software S4E