An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:horizoncloud:caterease:*:*:*:*:*:*:*:* |
Wed, 07 Aug 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T15:28:21.567300
Reserved: 2024-06-21T00:00:00
Link: CVE-2024-38882
Updated: 2024-08-03T18:29:04.642Z
Status : Analyzed
Published: 2024-08-02T18:16:19.300
Modified: 2025-05-05T15:07:13.760
Link: CVE-2024-38882
No data.
OpenCVE Enrichment
No data.
Weaknesses