RULE(RULE ID:338555)

Rule General Information
Release Date: 2024-11-19
Rule Name: Esafenet CDG DelHookService SQL Injection Vulnerability (CVE-2024-10660)
Severity:
CVE ID:
Rule Protection Details
Description: Esafenet CDG electronic document security management system is the earliest document encryption and decryption product in China based on file filtering and driving technology. The protection scope covers terminal computers (Windows, Mac, Linux system platforms), smart terminals (Android, IOS) and various application systems (OA, knowledge management, document management, project management, PDM, etc.). There is a sql injection vulnerability in this system. The vulnerability stems from the fact that the parameter HookId in the file/com/esafenet/servlet/policy/HookService.java can cause SQL injection.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.