CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-55160

Critical · CVSS 9.8

GFast — SQL Injection via unsanitized OrderBy parameter

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-89

Description

GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.

Search profile — drives PoC discovery

Symbols OrderBy/system/operLog/listsys_oper_log.gosysOperLogSysOperLogGetOperLogListos-v3.2
Keywords CVE-2024-55160GFast SQL injectionGFast OrderBy SQLigfast operLogtiger1103 gfastgfast os-v3.2 SQL injectiongfast /system/operLog/list
Versions: v2 to v3.2

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z