Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was learned that the product is not supported.
History

Fri, 13 Dec 2024 07:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 09 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Eryaz Information Technologies
Eryaz Information Technologies natracar B2b Dealer Management Program
CPEs cpe:2.3:a:eryaz_information_technologies:natracar_b2b_dealer_management_program:*:*:*:*:*:*:*:*
Vendors & Products Eryaz Information Technologies
Eryaz Information Technologies natracar B2b Dealer Management Program
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 09 Dec 2024 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was learned that the product is not supported.
Title Unauthenticated SQLi in Eryaz IT's NatraCar B2B Dealer Management Program
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published: 2024-12-09T13:23:06.505Z

Updated: 2024-12-13T07:16:05.030Z

Reserved: 2024-08-28T09:08:16.109Z

Link: CVE-2024-8259

cve-icon Vulnrichment

Updated: 2024-12-09T15:16:10.515Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-12-09T14:15:13.473

Modified: 2024-12-13T08:15:05.017

Link: CVE-2024-8259

cve-icon Redhat

No data.