CVE detail
CVE-2024-39309 — CVE-2024-39309
Published 2024-07-01 · Modified 2026-06-17 · Source nvd
CRITICAL
severity
CVSS-derived band
0.2017
EPSS probability
exploitation probability, 30d
97.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection has been improved in versions 6.5.7 and 7.1.0. No known workarounds are available.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References