A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2024-10617

CVE-2024-10617: Tongda2000 Office Anywhere SQLI Vulnerability

CVE-2024-10617 is a critical SQL injection vulnerability in Tongda2000 Office Anywhere that allows remote attackers to manipulate database queries. This article covers the technical details, affected versions, and mitigation.

Published: May 26, 2026

CVE-2024-10617 Overview

CVE-2024-10617 is a SQL injection vulnerability affecting Tongda Office Anywhere (Tongda OA) versions up to 11.10. The flaw resides in the /pda/workflow/check_seal.php endpoint, where the ID parameter is passed to a database query without proper sanitization. Authenticated remote attackers can manipulate this parameter to inject arbitrary SQL statements. Public disclosure of the exploit details increases the likelihood of opportunistic abuse against exposed Tongda OA instances. The weakness is tracked under CWE-89 (Improper Neutralization of Special Elements used in an SQL Command).

Critical Impact

Remote attackers with low-privileged access can extract, modify, or delete database records by injecting SQL through the ID parameter of check_seal.php.

Affected Products

  • Tongda2000 Office Anywhere versions up to and including 11.10
  • /pda/workflow/check_seal.php endpoint
  • Deployments exposing the PDA workflow module to untrusted networks

Discovery Timeline

  • 2024-11-01 - CVE-2024-10617 published to the National Vulnerability Database (NVD)
  • 2024-11-04 - Last updated in NVD database

Technical Details for CVE-2024-10617

Vulnerability Analysis

The vulnerability is a classic SQL injection in a PHP-based workflow component of Tongda OA. The check_seal.php script accepts the ID parameter from an HTTP request and concatenates it into a SQL query without parameterization or input validation. Attackers can supply crafted values to break out of the intended query context and append arbitrary SQL clauses.

Exploitation requires only low-level authenticated access and no user interaction. Because Tongda OA stores workflow records, user credentials, and document metadata in its backend database, successful injection can disclose sensitive business information. The impact spans limited confidentiality, integrity, and availability of data within the affected application instance.

Root Cause

The root cause is improper neutralization of user input (CWE-89) inside check_seal.php. The application directly inserts the ID parameter into a SQL statement rather than using prepared statements or stored procedures with bound parameters. No allow-list filtering or type casting is applied before the parameter reaches the database layer.

Attack Vector

The attack vector is network-based. An attacker sends a crafted HTTP request to /pda/workflow/check_seal.php with a malicious ID value containing SQL metacharacters and payloads such as UNION SELECT clauses or boolean-based blind injection probes. The server processes the query and returns data or behavior the attacker can use to enumerate the database schema and extract records. Public proof-of-concept discussion is referenced in the GitHub Issue Discussion and VulDB #282628.

No verified exploit code is reproduced here. See the linked VulDB CTI Report #282628 for additional technical context.

Detection Methods for CVE-2024-10617

Indicators of Compromise

  • HTTP requests targeting /pda/workflow/check_seal.php containing SQL metacharacters such as ', ", --, ;, or UNION in the ID parameter
  • Unusual database errors logged by the Tongda OA application around the workflow check_seal endpoint
  • Spikes in outbound database query volume originating from the Tongda OA web process
  • Web access logs showing repeated requests to check_seal.php from a single source with varying ID values

Detection Strategies

  • Deploy web application firewall (WAF) signatures that match SQL injection patterns against the ID parameter of check_seal.php
  • Inspect application and database logs for syntax errors, malformed queries, or unexpected UNION/SELECT clauses tied to the workflow module
  • Correlate authentication events with subsequent access to the vulnerable endpoint to identify low-privileged accounts probing the parameter

Monitoring Recommendations

  • Forward Tongda OA web server, PHP error, and database audit logs to a centralized logging or SIEM platform for correlation
  • Alert on any HTTP 500 responses from /pda/workflow/check_seal.php that follow requests containing encoded SQL syntax
  • Baseline normal query patterns from the OA application and flag deviations such as schema enumeration against information_schema

How to Mitigate CVE-2024-10617

Immediate Actions Required

  • Restrict network access to the Tongda OA application so that only trusted users and networks can reach /pda/workflow/check_seal.php
  • Apply WAF rules to block SQL metacharacters in the ID parameter until a vendor patch is verified and deployed
  • Audit Tongda OA user accounts and rotate credentials for any account that may have been used to probe the endpoint
  • Review database audit logs for evidence of prior exploitation, including unexpected SELECT activity against sensitive tables

Patch Information

At the time of publication, no vendor advisory or patch reference is listed in the NVD record. Administrators should monitor the Tongda OA vendor site and the VulDB entry #282628 for updated remediation guidance. Until an official fix is available, apply the workarounds below and upgrade to a release later than 11.10 once one is published by the vendor.

Workarounds

  • Place the Tongda OA application behind a reverse proxy or WAF that enforces strict input validation on the ID parameter
  • Limit database account privileges used by the OA application to the minimum required, preventing schema enumeration and write operations from the web tier
  • Disable or restrict the /pda/workflow/check_seal.php endpoint via web server configuration if the PDA workflow feature is not required
  • Enforce strong authentication and monitor authenticated sessions interacting with the workflow module
bash
# Example nginx location block to restrict access to the vulnerable endpoint
location = /pda/workflow/check_seal.php {
    allow 10.0.0.0/8;        # internal management network only
    deny  all;
    # Block requests where ID contains SQL metacharacters
    if ($arg_ID ~* "('|\"|--|;|union|select|/\*)") {
        return 403;
    }
    fastcgi_pass php_backend;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeSQLI

  • Vendor/TechTongda2000 Office Anywhere

  • SeverityMEDIUM

  • CVSS Score5.3

  • EPSS Probability0.10%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityLow
  • CWE References
  • CWE-89
  • Technical References
  • GitHub Issue Discussion

  • VulDB CTI Report #282628

  • VulDB #282628

  • VulDB Submission #433510
  • Related CVEs
  • CVE-2024-10655: Tongda2000 Office Anywhere SQL Injection

  • CVE-2024-10656: Tongda2000 Office Anywhere SQLi Flaw

  • CVE-2024-10657: Tongda2000 Office Anywhere SQLi Flaw

  • CVE-2024-10602: Tongda2000 Office Anywhere SQLi Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English