The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/en/cp-139-7961-c575f-2.html | Third Party Advisory |
https://www.twcert.org.tw/tw/cp-132-7960-0ee18-1.html | Third Party Advisory |
Configurations
History
10 Sep 2024, 21:16
Type | Values Removed | Values Added |
---|---|---|
First Time |
Simopro Technology
Simopro Technology winmatrix3 |
|
CPE | cpe:2.3:a:simopro_technology:winmatrix3:*:*:*:*:*:*:*:* | |
References | () https://www.twcert.org.tw/en/cp-139-7961-c575f-2.html - Third Party Advisory | |
References | () https://www.twcert.org.tw/tw/cp-132-7960-0ee18-1.html - Third Party Advisory |
29 Jul 2024, 14:12
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
29 Jul 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-29 03:15
Updated : 2024-09-10 21:16
NVD link : CVE-2024-7201
Mitre link : CVE-2024-7201
CVE.ORG link : CVE-2024-7201
JSON object : View
Products Affected
simopro_technology
- winmatrix3
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')