Sploitus

CVE-2024-45850

No indexed exploits for CVE-2024-45850 yet

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for site column creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.

Affected products
Sharepoint Server
Mindsdb
< 24.7.4.1
CVSS 3.1
8.8 HIGH
EPSS
0.9% (55th percentile)
Weakness
CWE-95, CWE-94
NVD status
Analyzed
Published
2024-09-12
Attack patterns
CAPEC-35
CVE-2024-45850 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-45850 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-45850 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.