CVE-2024-54761

BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bigantsoft:bigant_office_messenger_5:5.6.0.6:*:*:*:*:*:*:*

History

29 Sep 2025, 17:43

Type Values Removed Values Added
CPE cpe:2.3:a:bigantsoft:bigant_office_messenger_5:5.6.0.6:*:*:*:*:*:*:*
First Time Bigantsoft
Bigantsoft bigant Office Messenger 5
References () https://gist.github.com/nscan9/a31982c90ab40a8e00373bf15efbf52a - () https://gist.github.com/nscan9/a31982c90ab40a8e00373bf15efbf52a - Third Party Advisory
References () https://github.com/nscan9/BigAnt-Office-Messenger-5.6.06-RCE-via-SQL-Injection/ - () https://github.com/nscan9/BigAnt-Office-Messenger-5.6.06-RCE-via-SQL-Injection/ - Exploit, Third Party Advisory

10 Jan 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) BigAnt Office Messenger 5.6.06 es vulnerable a la inyección SQL a través del parámetro 'dev_code'.
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.3

09 Jan 2025, 22:15

Type Values Removed Values Added
References
  • () https://gist.github.com/nscan9/a31982c90ab40a8e00373bf15efbf52a -

09 Jan 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-09 20:15

Updated : 2025-09-29 17:43


NVD link : CVE-2024-54761

Mitre link : CVE-2024-54761

CVE.ORG link : CVE-2024-54761


JSON object : View

Products Affected

bigantsoft

  • bigant_office_messenger_5
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')