CVE-2024-7026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

09 Jan 2025, 14:15

Type Values Removed Values Added
CWE CWE-564 CWE-89
Summary
  • (es) Inyección SQL: la vulnerabilidad de Hibernate en el software de seguimiento de vehículos de circuito cerrado de Teknogis Informatics permite la inyección SQL y la inyección SQL ciega. Este problema afecta al software de seguimiento de vehículos de circuito cerrado hasta el 21 de noviembre de 2024. NOTA: Se contactó al proveedor con anticipación sobre esta divulgación, pero no respondió de ninguna manera.
Summary (en) SQL Injection: Hibernate vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

21 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-21 14:15

Updated : 2025-01-09 14:15


NVD link : CVE-2024-7026

Mitre link : CVE-2024-7026

CVE.ORG link : CVE-2024-7026


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')