{"id":"CVE-2024-58290","title":"Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter","summary":"Xhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNIO…","severity":"none","cwe":["CWE-89"],"published":"2025-12-11","updated":"2026-10-02","sourceUpdated":"2026-10-02T00:10:00.180","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-58290","references":[{"url":"https://elements.envato.com/xhibiter-nft-marketplace-html-template-AQN45FA","label":"disclosure@vulncheck.com"},{"url":"https://www.exploit-db.com/exploits/52060","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/xhibiter-nft-marketplace-sql-injection-via-collections-endpoint","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"epss":0.00355,"epssPercentile":0.26867,"exploits":{"github":1,"githubRepos":["https://github.com/SohelYousef/CVE-2024-58290-Xhibiter-SQLi"],"checkedAt":"2026-10-02T01:06:29.933Z"},"exploitAvailable":true,"ingestedAt":"2026-10-02T01:05:54.715Z","slug":"CVE-2024-58290","body":"## Overview\n\nXhibiter NFT Marketplace 1.10.2 contains a SQL injection vulnerability in the collections endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or manipulate database information by sending crafted payloads to the collections page.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}