References https://www.secevery.com/toAticleInfo?id=20f065f3388f03203fd2e0db10b4cc79 https://avd.aliyun.com/detail?id=AVD-2024-24112 https://stack.chaitin.com/vuldb/detail/cf7d33cb-9b4a-4ed2-be3b-0e3a2b27755f https://cn-sec.com/archives/2507765.html https://cn-sec.com/archives/2507235.html https://cn-sec.com/archives/2508837.html https://cn-sec.com/archives/tag/xmall https://www.secevery.com/toArticleList?page=16 https://blog.csdn.net/m0_74653634/article/details/147998019 https://github.com/LaoW1823/POC-EXP https://github.com/Kelichen1113/POC-EXP https://nvd.nist.gov/vuln/detail/CVE-2024-24112 https://www.sentinelone.com/vulnerability-database/cve-2024-24112/ https://www.tenable.com/cve/CVE-2024-24112 https://github.com/advisories/GHSA-qv88-9x4p-qm78 https://osv.dev/vulnerability/CVE-2024-24112 https://pentest-tools.com/vulnerabilities-exploits/exrick-xmall-sql-injection_22893 https://cve.yack.one/cve/CVE-2024-24112 https://www.nsfocus.net/vulndb/97184 https://cve.imfht.com/detail/CVE-2024-24112
Related VulnerabilitiesXMall /item/list SQL 注入漏洞(CVE-2024-24112)Exrick Xboot Swagger SecurityController.java服务器端请求伪造(CVE-2025-8527)PoCCVE-2022-24112: Apache APISIX - Remote Code ExecutionPoCCVE-2024-24112: Exrick XMall - SQL InjectionPoCCVE-2022-24112: Apache APISIX apisix/batch-requests RCEPoCCVE-2024-24112: Exrick XMall 开源商城 SQL注入漏洞XMall商城listSearch存在SQL注入漏洞XMall 开源商城 存在SQL注入(CVE-2024-24112)Apache APISIX Dashboard命令执行漏洞(CVE-2022-24112)