Metrics
Affected Vendors & Products
Wed, 30 Oct 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Esafenet
Esafenet cdg |
|
CPEs | cpe:2.3:a:esafenet:cdg:5:*:*:*:*:*:*:* | |
Vendors & Products |
Esafenet
Esafenet cdg |
|
Metrics |
ssvc
|
Wed, 30 Oct 2024 00:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, was found in ESAFENET CDG 5. This affects the function findById of the file /com/esafenet/servlet/document/ExamCDGDocService.java. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | ESAFENET CDG ExamCDGDocService.java findById sql injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-10-30T00:00:12.843Z
Updated: 2024-10-30T15:00:04.338Z
Reserved: 2024-10-29T17:29:17.810Z
Link: CVE-2024-10501
Updated: 2024-10-30T13:43:42.713Z
Status : Analyzed
Published: 2024-10-30T01:15:03.107
Modified: 2024-11-06T17:20:32.857
Link: CVE-2024-10501
No data.