Логотип exploitDog
bind:CVE-2024-26264
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-26264

Количество 2

Количество 2

nvd логотип

CVE-2024-26264

почти 2 года назад

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7fvc-6vcj-hq22

почти 2 года назад

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-26264

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
github логотип
GHSA-7fvc-6vcj-hq22

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.

CVSS3: 9.8
0%
Низкий
почти 2 года назад

Уязвимостей на страницу