RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-05-08T00:00:00
Updated: 2024-08-01T23:44:09.468Z
Reserved: 2024-02-07T00:00:00
Link: CVE-2024-25524
Vulnrichment
Updated: 2024-08-01T23:44:09.468Z
NVD
Status : Awaiting Analysis
Published: 2024-05-08T15:15:08.253
Modified: 2024-07-03T01:49:03.920
Link: CVE-2024-25524
Redhat
No data.