CVE-2024-42994

VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module.
Configurations

No configuration.

History

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) VTiger CRM &lt;= 8.1.0 no desinfecta adecuadamente la entrada del usuario antes de usarla en una declaración SQL, lo que genera una inyección de SQL en la operación "CompanyDetails" del módulo "MailManager".

16 Aug 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2
CWE CWE-89

16 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-16 17:15

Updated : 2024-08-19 13:00


NVD link : CVE-2024-42994

Mitre link : CVE-2024-42994

CVE.ORG link : CVE-2024-42994


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')