Description
A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49589 | A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data. |
References
History
Fri, 29 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siempelkamp
Siempelkamp umweltoffice |
|
| CPEs | cpe:2.3:a:siempelkamp:umweltoffice:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Siempelkamp
Siempelkamp umweltoffice |
|
| Metrics |
ssvc
|
Thu, 28 Nov 2024 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data. | |
| Title | Siempelkamp: SQL injection due to improper handling of HTTP request input data | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2024-11-29T19:07:16.321Z
Reserved: 2024-08-29T13:20:48.703Z
Link: CVE-2024-8308
Updated: 2024-11-29T19:06:53.130Z
Status : Received
Published: 2024-11-28T11:15:54.697
Modified: 2024-11-28T11:15:54.697
Link: CVE-2024-8308
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD