CVE-2023-24221 | LuckyframeWEB 3.5 /system/DeptMapper.xml dataScope sql injection (Issue 23 / EUVD-2023-28280)
A vulnerability identified as critical has been detected in LuckyframeWEB 3.5. This issue affects some unknown processing of the file /system/DeptMapper.xml. This manipulation of the argument dataScope causes sql injection.
This vulnerability is registered as CVE-2023-24221. The attack requires access to the local network. No exploit is available.