CVE-2024-8259

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024. NOTE: The vendor was contacted and it was learned that the product is not supported.
Configurations

No configuration.

History

13 Dec 2024, 08:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 9.8
Summary
  • (es) Vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando SQL ("inyección SQL") en Eryaz Information Technologies NatraCar B2B Dealer Management Program permite la inyección SQL. Este problema afecta al programa de gestión de distribuidores B2B de NatraCar hasta el 09.12.2024. NOTA: Se contactó al proveedor y se supo que el producto no recibe soporte.

09 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 14:15

Updated : 2024-12-13 08:15


NVD link : CVE-2024-8259

Mitre link : CVE-2024-8259

CVE.ORG link : CVE-2024-8259


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')