SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a specially crafted SQL query to the ‘email’ parameter on the ‘RequestPasswordChange’ endpoint.

Project Subscriptions

Vendors Products
Tai Smart Factory Subscribe
Qplant Sf Subscribe
Taismartfactory Subscribe
Qplant Sf Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-50215 SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a specially crafted SQL query to the ‘email’ parameter on the ‘RequestPasswordChange’ endpoint.
Fixes

Solution

The vulnerability is fixed in all operational versions, so as of 17/10/2024, the current version distributed and updates to existing versions have the vulnerability resolved.


Workaround

No workaround given by the vendor.

History

Thu, 17 Oct 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Taismartfactory
Taismartfactory qplant Sf
CPEs cpe:2.3:a:taismartfactory:qplant_sf:1.0:*:*:*:*:*:*:*
Vendors & Products Taismartfactory
Taismartfactory qplant Sf

Tue, 15 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Tai Smart Factory
Tai Smart Factory qplant Sf
CPEs cpe:2.3:a:tai_smart_factory:qplant_sf:*:*:*:*:*:*:*:*
Vendors & Products Tai Smart Factory
Tai Smart Factory qplant Sf
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 09:00:00 +0000

Type Values Removed Values Added
Description SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information by sending a specially crafted SQL query to the ‘email’ parameter on the ‘RequestPasswordChange’ endpoint.
Title SQL injection in QPLANT by TAI Smart Factory
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-10-17T11:48:53.608Z

Reserved: 2024-10-14T07:30:30.217Z

Link: CVE-2024-9925

cve-icon Vulnrichment

Updated: 2024-10-15T13:46:24.408Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T09:15:03.990

Modified: 2024-10-17T18:09:40.537

Link: CVE-2024-9925

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses