Security Advisory

CVE-2024-42844

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-06 00:00:00
Last updated 2025-03-06 16:13:22
Assigner mitre
State PUBLISHED

Description

A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information