CVE-2024-29401: Mindskip Xzs-MySQL
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.
Affected products
- Mindskip Xzs-MySQL: version 3.8 only
Published 2024-03-26. Last modified 2026-06-17.