{"id":"CVE-2024-35374","aliases":["PYSEC-2026-426"],"url":"https://o3.security/vulnerability/CVE-2024-35374","summary":"Mocodo vulnerable to SQL injection in `/web/generate.php`","details":"Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the `sql_case` input field in `/web/generate.php`, allowing remote attackers to execute arbitrary SQL commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.","published":"2024-05-28T20:20:37Z","modified":"2026-06-29T12:26:13.083506026Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mocodo","fixedVersion":"4.2.7"}],"fix":{"url":"https://github.com/laowantong/mocodo/commit/f9368df28518b6c4a92fd207c260f1978ec34d6e","label":"laowantong/mocodo@f9368df"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35374"},{"type":"WEB","url":"https://github.com/laowantong/mocodo/commit/f9368df28518b6c4a92fd207c260f1978ec34d6e"},{"type":"WEB","url":"https://chocapikk.com/posts/2024/mocodo-vulnerabilities"},{"type":"PACKAGE","url":"https://github.com/laowantong/mocodo"},{"type":"WEB","url":"https://github.com/laowantong/mocodo/blob/11ca879060a68e06844058cd969c6379214cc2a8/web/generate.php#L104-L158"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-29T12:26:13.083506026Z"}}