CVE-2024-55160
Critical · CVSS 9.8GFast — SQL Injection via unsanitized OrderBy parameter
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-89
Description
GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.
Search profile — drives PoC discovery
Symbols OrderBy/system/operLog/listsys_oper_log.gosysOperLogSysOperLogGetOperLogListos-v3.2
Keywords CVE-2024-55160GFast SQL injectionGFast OrderBy SQLigfast operLogtiger1103 gfastgfast os-v3.2 SQL injectiongfast /system/operLog/list
Versions: v2 to v3.2
References
- https://github.com/SuperDu1/CVE/issues/2
- https://github.com/tiger1103/gfast/blob/os-v3.2/api/v1/system/sys_oper_log.go#L35
- https://github.com/tiger1103/gfast/blob/os-v3.2/internal/app/system/logic/sysOperLog/sys_oper_log.go#L121
- https://github.com/tiger1103/gfast/tree/os-v3.2
- https://github.com/SuperDu1/CVE/issues/2
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z