Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
References
Configurations
No configuration.
History
10 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-10 22:15
Updated : 2025-01-10 22:15
NVD link : CVE-2024-9134
Mitre link : CVE-2024-9134
CVE.ORG link : CVE-2024-9134
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')