By weakness (CWE)

CWE-564: related vulnerabilities

CVEs classified under CWE-564. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2024-58352HIGH 7.5

    Landray OA, a collaboration and office automation platform, contains a critical flaw that allows attackers to bypass authentication entirely and extract sensitive information directly from the database. The vulnerability exists in the login helper functionality, where user input is not properly validated before being used to construct database queries. An attacker can craft a specially-formatted request to retrieve administrator credentials, database records, or—in certain configurations—write arbitrary files to the server, leading to complete system compromise. This is a post-authentication-bypass, pre-RCE chain that significantly expands the attack surface.