CVE-2024-7201

The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simopro_technology:winmatrix3:*:*:*:*:*:*:*:*

History

10 Sep 2024, 21:16

Type Values Removed Values Added
First Time Simopro Technology
Simopro Technology winmatrix3
CPE cpe:2.3:a:simopro_technology:winmatrix3:*:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-7961-c575f-2.html - () https://www.twcert.org.tw/en/cp-139-7961-c575f-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-7960-0ee18-1.html - () https://www.twcert.org.tw/tw/cp-132-7960-0ee18-1.html - Third Party Advisory

29 Jul 2024, 14:12

Type Values Removed Values Added
Summary
  • (es) La funcionalidad de inicio de sesión del paquete web WinMatrix3 de Simopro Technology carece de una validación adecuada de la entrada del usuario, lo que permite a atacantes remotos no autenticados inyectar comandos SQL para leer, modificar y eliminar contenidos de la base de datos.

29 Jul 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-29 03:15

Updated : 2024-09-10 21:16


NVD link : CVE-2024-7201

Mitre link : CVE-2024-7201

CVE.ORG link : CVE-2024-7201


JSON object : View

Products Affected

simopro_technology

  • winmatrix3
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')