A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 29 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Siempelkamp
Siempelkamp umweltoffice
CPEs cpe:2.3:a:siempelkamp:umweltoffice:*:*:*:*:*:*:*:*
Vendors & Products Siempelkamp
Siempelkamp umweltoffice
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Nov 2024 10:45:00 +0000

Type Values Removed Values Added
Description A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.
Title Siempelkamp: SQL injection due to improper handling of HTTP request input data
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-11-29T19:07:16.321Z

Reserved: 2024-08-29T13:20:48.703Z

Link: CVE-2024-8308

cve-icon Vulnrichment

Updated: 2024-11-29T19:06:53.130Z

cve-icon NVD

Status : Received

Published: 2024-11-28T11:15:54.697

Modified: 2024-11-28T11:15:54.697

Link: CVE-2024-8308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.