CVE-2024-26264

CVSS V2 None CVSS V3 None
Description
EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.
Overview
  • CVE ID
  • CVE-2024-26264
  • Assigner
  • twcert
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-15T03:02:37.196Z
  • Last Modified Date
  • 2024-02-15T03:02:37.196Z
References
Reference URL Reference Tags
https://www.twcert.org.tw/tw/cp-132-7677-b1c0f-1.html third-party-advisory
History
Created Old Value New Value Data Type Notes
2024-06-26 00:48:55 Added to TrackCVE