SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.
Fixes

Solution

The vulnerabilities have been resolved in versions 4.7 and later.


Workaround

No workaround given by the vendor.

History

Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Badgermeter
Badgermeter monitool
CPEs cpe:2.3:a:badgermeter:monitool:*:*:*:*:*:*:*:*
Vendors & Products Badgermeter
Badgermeter monitool

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-12T14:48:20.912Z

Reserved: 2024-02-07T10:22:53.616Z

Link: CVE-2024-1301

cve-icon Vulnrichment

Updated: 2024-08-01T18:33:25.485Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-12T16:15:07.187

Modified: 2025-02-26T15:15:08.143

Link: CVE-2024-1301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.