A vulnerability classified as critical was found in Xhibiter NFT Marketplace 1.10.2. This affects an unknown function of the component Collections Endpoint. Such manipulation of the argument ID leads to sql injection. This vulnerability is traded as CVE-2024-58290. The attack may be launched remotely. Furthermore, there is an exploit available. Weiterlesen: CVE-2024-58290 | Xhibiter NFT Marketplace 1.10.2 Collections Endpoint…
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2024-58290 | Xhibiter NFT Marketplace 1.10.2 Collections Endpoint id sql injection (Exploit 52060 / EDB-52060)
A vulnerability classified as critical was found in Xhibiter NFT Marketplace 1.10.2. This affects an unknown function of the component Collections Endpoint.…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
Compliance, SLA & Vendor Adherence
Advisory-Prüfung · Score-Einordnung · Fristen
CISA-SSVC-Triage (vulnrichment)CVE-2024-58290
Exploitation: poc (PoC verfügbar)Automatable: yes (Automatisierbar)Technical Impact: total (Vollständig)
Quelle: CISA-ADP vulnrichment · Stand 2025-12-18T19:47:07.202588Z · CISA Coordinator
Advisory Radar
Workaround & Virtual-Patching empfohlen
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Öffentliche PoCs existieren. Isolieren Sie das System oder wenden Sie Micro-Segmentierungsregeln an, bis offizielle Patches vorliegen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referenceelements.envato.com
2 öffentliche Exploit-Referenz(en) detektiert (Exploit Database (EDB)).
PoC einsehen