S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Aug 25, 2024

CVE-2024-7188 Scanner

CVE-2024-7188 scanner - SQL Injection vulnerability in Bylancer Quicklancer

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-7188
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of the component GET Parameter Handler. The manipulation of the argument range2 leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-272609 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Quicklancerby Bylancer
2.4
quicklancerby bylancer
2.4
Updated Sep 10, 2026View on NVD →
Detail

Bylancer Quicklancer is a PHP-based freelance marketplace script that allows users to create platforms for hiring freelancers. It is used by individuals and companies to post jobs, manage freelancers, and handle payments. The software is popular for building customized freelance platforms. Quicklancer integrates various features such as job posting, bidding, and escrow services. It is especially favored by those looking for an affordable and customizable solution for freelance marketplaces.

The vulnerability exists in the "range2" parameter within the Quicklancer platform, allowing an attacker to perform SQL injection. This vulnerability can be exploited without authentication, making it particularly dangerous. The attack vector involves injecting SQL queries into the database through a manipulated HTTP request. As a result, an attacker could gain unauthorized access to sensitive data or disrupt database operations.

The vulnerable endpoint in Quicklancer is the GET request to the /listing page, specifically targeting the "range2" parameter. The vulnerability allows for both time-based and boolean-based blind SQL injection. By manipulating this parameter, an attacker can execute arbitrary SQL commands, potentially extracting sensitive information or altering the database's content. The attack can be carried out remotely by an unauthenticated user, making it a high-risk issue.

If exploited, this vulnerability could lead to unauthorized data access, data leakage, or database corruption. An attacker could potentially retrieve user credentials, financial information, or other sensitive data. Additionally, the attacker might be able to alter or delete important data, leading to loss of service or integrity. This could severely impact the platform's operation, user trust, and overall security.

Protect your freelance marketplace and ensure your platform's integrity with S4E's comprehensive vulnerability scanner. Our platform provides continuous monitoring, detailed reports, and actionable insights, helping you to maintain a secure and trustworthy environment for your users. By becoming a member, you gain access to a wide range of tools and features designed to safeguard your digital assets. Start securing your platform today with our industry-leading services.

References:

Solution Advice
  • Validate and sanitize user inputs to prevent SQL injection attacks.
  • Use prepared statements or parameterized queries for database interactions.
  • Implement proper error handling to avoid exposing sensitive information.
  • Regularly update your software to patch known vulnerabilities.
  • Conduct security audits and penetration testing to identify potential weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-7188 scanner - SQL Injection vulnerability in Bylancer Quicklancer | S4E