Beveiligingsadvies

CVE-2024-6527

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-07-09 13:30:44
Laatst bijgewerkt 2024-08-01 21:41:03
Toegewezen door CERT-PL
CVSS-score 9.3
Status PUBLISHED

Beschrijving

SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disclose the contents of the database and obtain administrator's token to modify the content of pages.  This issue affects MegaBIP software versions through 5.13.