A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-26730 A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.
Fixes

Solution

Vulnerability has been fixed in later versions.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-06T14:56:52.651Z

Reserved: 2024-03-19T07:42:30.141Z

Link: CVE-2024-29732

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:55.524Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-21T11:15:28.390

Modified: 2024-11-21T09:08:11.323

Link: CVE-2024-29732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses