Show filters
203 Total Results
Displaying 21-30 of 203
Sort by:
Attacker Value
Unknown
CVE-2024-45854
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.
0
Attacker Value
Unknown
CVE-2024-45853
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.
0
Attacker Value
Unknown
CVE-2024-45852
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
0
Attacker Value
Unknown
CVE-2024-45851
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list item creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.
0
Attacker Value
Unknown
CVE-2024-45850
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for site column creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.
0
Attacker Value
Unknown
CVE-2024-45849
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.
0
Attacker Value
Unknown
CVE-2024-45848
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is run against a database created with the ChromaDB engine, the code will be passed to an eval function and executed on the server.
0
Attacker Value
Unknown
CVE-2024-45847
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is run against a database created with the specified integration engine, the code will be passed to an eval function and executed on the server.
0
Attacker Value
Unknown
CVE-2024-45846
Disclosure Date: September 12, 2024 (last updated September 17, 2024)
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT WHERE’ clause containing Python code is run against a database created with the Weaviate engine, the code will be passed to an eval function and executed on the server.
0
Attacker Value
Unknown
CVE-2024-5799
Disclosure Date: September 12, 2024 (last updated September 27, 2024)
The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
0