← Back to browse · API

CVE-2024-39309

Severity
CRITICAL
CVSS
9.8
EPSS
0.20171
Risk score
46.26
CISA KEV
No
PoC
No
Published
2024-07-01
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-2315, GHSA-C2HR-CQG6-8J6R
Products
parse-community:parse-server 7.0.0, < 7.1.0, parse-community:parse-server < 6.5.7
Sources
euvd EUVD-2024-2315

Description

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and 7.1.0. No known workarounds are available.

References