CVE-2024-8749
CVSS V2 None
CVSS V3 None
Description
SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/modules/api/model/cmdb/isys_api_model_cmdb_objects_by_relation.class.php and retrieve all the information stored in the database.
Overview
- CVE ID
- CVE-2024-8749
- Assigner
- INCIBE
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-12T11:36:55.184Z
- Last Modified Date
- 2024-09-12T12:57:48.913Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-synetics-idoit-pro |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-8749 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8749 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-09-13 13:07:29 | Added to TrackCVE |