CVE-2024-32738 Scanner

Targets the query_ptask_lean endpoint in PowerPanel Enterprise, allowing attackers to inject arbitrary SQL queries and extract sensitive database contents.

Short Info


Level

High

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

12 days 11 hours

Scan only one

URL

Toolbox

CyberPower PowerPanel Enterprise is a centralized management platform used by IT administrators to monitor, control, and automate uninterruptible power supplies (UPS) across data centers, server rooms, and enterprise networks. It provides real-time alerts, remote configuration, and power event logging to ensure business continuity during outages. The software integrates with critical infrastructure to optimize power usage and prevent data loss, making it a key component in many organizations' disaster recovery strategies.

CVE-2024-32738 is a SQL injection vulnerability that arises due to insufficient sanitization of user-supplied input before it is incorporated into database queries. The flaw exists in the application's handling of parameters passed to the query_ptask_lean function, which fails to properly escape or validate data. This allows an attacker to manipulate SQL statements by injecting malicious payloads through the vulnerable parameter.

Specifically, the vulnerability is located in the query_ptask_lean function, which processes requests to retrieve task-related information from the database. The affected endpoint does not enforce strict input validation, enabling an unauthenticated attacker to craft HTTP requests containing SQL injection payloads. By exploiting this, the attacker can execute arbitrary SQL commands, potentially bypassing authentication or accessing unauthorized data.

If successfully exploited, an attacker could extract sensitive information such as user credentials, configuration details, or operational logs from the database. This could lead to unauthorized access to the PowerPanel Enterprise system, enabling further attacks on connected UPS devices and network infrastructure. The CVSS score of 7.5 reflects the high potential for data compromise and system disruption, emphasizing the need for immediate remediation.

Get started to protecting your digital assets