'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2024-7099,CVE-2024-25722:NetEase QAnything SQL Injection Vulnerability
Severity:critical
CVE ID:CVE-2024-7099 CVE-2024-25722
| Descripiton:
|
NetEase QAnything is a local knowledge base question-answering system developed by NetEase, Inc., which is designed to support arbitrary file formats or databases and can be installed and used offline. The version 1.4.1 of NetEase QAnything has a SQL injection vulnerability. This vulnerability arises because unsafe data obtained from user input is concatenated into SQL queries, thereby leading to SQL injection. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.