Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Fixes

Solution

Contact the vendor to install the patch.


Workaround

No workaround given by the vendor.

History

Thu, 21 Nov 2024 07:30:00 +0000


Tue, 15 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Changate
Changate property Management System
CPEs cpe:2.3:a:changate:property_management_system:*:*:*:*:*:*:*:*
Vendors & Products Changate
Changate property Management System
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 06:45:00 +0000

Type Values Removed Values Added
Description Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Title ChanGate Property Management System - SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2025-01-09T17:27:56.816Z

Reserved: 2024-10-15T02:36:11.219Z

Link: CVE-2024-9972

cve-icon Vulnrichment

Updated: 2024-10-15T13:35:35.120Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2024-10-15T07:15:02.750

Modified: 2024-11-21T11:15:38.670

Link: CVE-2024-9972

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.