CVE-2024-32212

SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings components.
Configurations

No configuration.

History

21 Nov 2024, 09:14

Type Values Removed Values Added
References () https://gainsec.com/2024/04/28/cve-2024-32210-cve-2024-32211-cve-2024-32212-cve-2024-32213-lomag-integrator-ce-warehouse-management/ - () https://gainsec.com/2024/04/28/cve-2024-32210-cve-2024-32211-cve-2024-32212-cve-2024-32213-lomag-integrator-ce-warehouse-management/ -

03 Jul 2024, 01:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
CWE CWE-89
Summary
  • (es) Vulnerabilidad de inyección SQL en LOGINT LoMag Inventory Management v1.0.20.120 y anteriores permite a un atacante ejecutar código arbitrario a través de los componentes ArticleGetGroups, DocAddDocument, ClassClickShop y frmSettings.

01 May 2024, 19:50

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-01 18:15

Updated : 2024-11-21 09:14


NVD link : CVE-2024-32212

Mitre link : CVE-2024-32212

CVE.ORG link : CVE-2024-32212


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')