Description
A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.
Published: 2024-03-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Vulnerability has been fixed in later versions.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-26730 A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-06T14:56:52.651Z

Reserved: 2024-03-19T07:42:30.141Z

Link: CVE-2024-29732

cve-icon Vulnrichment

Updated: 2024-08-02T01:10:55.524Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-21T11:15:28.390

Modified: 2024-11-21T09:08:11.323

Link: CVE-2024-29732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses