A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the 'user_id' parameter in the raw SQL query used for deleting users. An attacker can exploit this vulnerability by injecting malicious SQL commands through the 'user_id' parameter, leading to potential unauthorized access to sensitive information such as API keys, user information, and tokens stored in the database. The affected version is 1.27.14.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-06-06T18:23:49.593Z
Updated: 2024-06-07T19:36:25.329Z
Reserved: 2024-05-14T22:59:45.190Z
Link: CVE-2024-4890
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-06-06T19:16:03.630
Modified: 2024-06-07T14:56:05.647
Link: CVE-2024-4890
JSON object: View
Redhat Information
No data.
CWE