CVE-2024-9972

Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Configurations

No configuration.

History

21 Nov 2024, 11:15

Type Values Removed Values Added
References
  • () https://www.chtsecurity.com/news/4552fc54-18af-4c18-972d-394a68e44a39 -
  • () https://www.chtsecurity.com/news/8585c924-4a27-4337-bb44-684adc206432 -

15 Oct 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Property Management System de ChanGate tiene una vulnerabilidad de inyección SQL, que permite a atacantes remotos no autenticados inyectar comandos SQL arbitrarios para leer, modificar y eliminar contenidos de bases de datos.

15 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-15 07:15

Updated : 2024-11-21 11:15


NVD link : CVE-2024-9972

Mitre link : CVE-2024-9972

CVE.ORG link : CVE-2024-9972


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')