There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
References
Configurations
History
22 Oct 2024, 16:10
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://www.hikvision.com/en/support/cybersecurity/security-advisory/security-vulnerabilities-in-hikcentral-product-series/ - Vendor Advisory | |
CPE | cpe:2.3:a:hikvision:hikcentral_professional:*:*:*:*:*:*:*:* | |
CWE | CWE-89 | |
First Time |
Hikvision hikcentral Professional
Hikvision |
18 Oct 2024, 12:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
18 Oct 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-18 09:15
Updated : 2024-10-22 16:10
NVD link : CVE-2024-47487
Mitre link : CVE-2024-47487
CVE.ORG link : CVE-2024-47487
JSON object : View
Products Affected
hikvision
- hikcentral_professional
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')