CVE-2024-6680 | witmy my-springsecurity-plus up to 2024-07-04 /api/dept/build params.dataScope sql injection (Duplicate CVE-2024-40541 / IAAH8A)
A vulnerability classified as critical was found in witmy my-springsecurity-plus up to 2024-07-04. This affects an unknown part of the file /api/dept/build. The manipulation of the argument params.dataScope results in sql injection.
This vulnerability is reported as CVE-2024-6680. The attack can be launched remotely. Moreover, an exploit is present.
It appears that this entry has been assigned a duplicate CVE-2024-40541.