Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00287}

epss

{'score': 0.00283}


Tue, 24 Jun 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Ketr
Ketr jepaas
CPEs cpe:2.3:a:ketr:jepaas:7.2.8:*:*:*:*:*:*:*
Vendors & Products Ketr
Ketr jepaas

Mon, 09 Dec 2024 17:00:00 +0000

Type Values Removed Values Added
References

Tue, 03 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Jepaas
Jepaas jepaas
Weaknesses CWE-89
CPEs cpe:2.3:a:jepaas:jepaas:*:*:*:*:*:*:*:*
Vendors & Products Jepaas
Jepaas jepaas
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 15:45:00 +0000

Type Values Removed Values Added
Description Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-01-06T17:56:54.163Z

Reserved: 2024-10-28T00:00:00

Link: CVE-2024-51164

cve-icon Vulnrichment

Updated: 2024-12-03T16:39:02.055Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-15T16:15:37.057

Modified: 2025-06-24T14:37:12.777

Link: CVE-2024-51164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.