S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 16, 2024

CVE-2024-32739 Scanner

CVE-2024-32739 Scanner - SQL Injection vulnerability in CyberPower PowerPanel Enterprise

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-32739
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within MCUDBHelper.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
CyberPower PowerPanel Enterpriseby CyberPower
AFFECTED< 2.8.3SAFE ✓≥ 2.8.3
powerpanel_enterpriseby cyberpower
AFFECTED< 2.8.3SAFE ✓≥ 2.8.3
Updated Aug 22, 2026View on NVD →
Detail

CyberPower PowerPanel Enterprise is a powerful management tool designed for IT professionals and system administrators to streamline their operations. This software plays a critical role in energy management for data centers, providing centralized control over multiple devices. It is primarily employed to manage networked UPS systems to ensure smooth functioning in case of power issues. Often utilized in large-scale enterprises and server rooms, it helps in maintaining system uptime and efficiency. Users rely on this product for real-time monitoring, event notifications, and data collection. The software is praised for its ability to minimize downtime, secure IT environments, and integrate with third-party applications.

The SQL Injection vulnerability in CyberPower PowerPanel Enterprise allows an attacker to manipulate database queries through unsanitized input. This specific vulnerability exists in versions prior to v2.8.3. It can be exploited through the "query_ptask_verbose" function within the MCUDBHelper component. An attacker could potentially craft unauthorized database queries to access sensitive information. As a common web security issue, SQL Injection can lead to major security breaches if not addressed in a timely manner. Protecting databases from such attacks is crucial for maintaining the confidentiality and integrity of data.

Technical analysis of this SQL Injection vulnerability reveals that it is executed via a crafted GET request. The vulnerable endpoint, "/api/v1/ndconfig," can be exploited by injecting malicious SQL commands using the UNION operator to retrieve unauthorized data, including database versioning. Successful exploitation requires no authentication, increasing the risk significantly. Matchers within the HTTP response help in identifying the flaw when certain patterns like the 'application/json' content type and specific words in the body are detected. This enables detection of when the vulnerability is being exploited, leading to data leakage.

Exploiting the SQL Injection vulnerability in CyberPower PowerPanel Enterprise can lead to unauthorized data leakage. Attackers can gain access to sensitive information such as user credentials and system configurations. Such breaches could compromise the entire network infrastructure if used for lateral movement. The impact may also extend to loss of sensitive operational data, potentially disrupting business continuity. It further exposes organizations to compliance violations and penalties if confidential data is exposed.

REFERENCES

Solution Advice
  • Update to CyberPower PowerPanel Enterprise v2.8.3 or later to patch the vulnerability.
  • Regularly audit and sanitize user inputs on the application to prevent SQL injection.
  • Implement a Web Application Firewall (WAF) to filter and monitor web traffic for malicious activity.
  • Conduct periodic security testing and vulnerability assessments to catch similar issues early.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.