Description

Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

INFO

Published Date :

2024-11-15T00:00:00.000Z

Last Modified :

2025-01-06T17:56:54.163Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-51164 vulnerability.

Vendors Products
Jepaas
  • Jepaas
Ketr
  • Jepaas

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact