Description
SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-26859 | SQL injection vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter./sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted query to the server and extract all the data from it. |
References
History
Fri, 24 Jan 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sapplica
Sapplica sentrifugo |
|
| CPEs | cpe:2.3:a:sapplica:sentrifugo:3.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Sapplica
Sapplica sentrifugo |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-02T01:17:58.141Z
Reserved: 2024-03-21T10:29:38.100Z
Link: CVE-2024-29870
Updated: 2024-08-02T01:17:58.141Z
Status : Analyzed
Published: 2024-03-21T14:15:07.867
Modified: 2025-01-24T18:18:36.670
Link: CVE-2024-29870
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD