CVE-2024-8329

6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.
Configurations

Configuration 1 (hide)

cpe:2.3:a:6shr_system_project:6shr_system:*:*:*:*:*:*:*:*

History

05 Sep 2024, 13:40

Type Values Removed Values Added
Summary
  • (es) El sistema 6SHR de Gether Technology no valida correctamente el parámetro de página específico, lo que permite a atacantes remotos con privilegios regulares inyectar comandos SQL para leer, modificar y eliminar contenidos de la base de datos.
References () https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html - () https://www.twcert.org.tw/en/cp-139-8034-657b7-2.html - Vendor Advisory
References () https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html - () https://www.twcert.org.tw/tw/cp-132-8030-e2eac-1.html - Vendor Advisory
CPE cpe:2.3:a:6shr_system_project:6shr_system:*:*:*:*:*:*:*:*
First Time 6shr System Project 6shr System
6shr System Project

30 Aug 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-30 03:15

Updated : 2024-09-05 13:40


NVD link : CVE-2024-8329

Mitre link : CVE-2024-8329

CVE.ORG link : CVE-2024-8329


JSON object : View

Products Affected

6shr_system_project

  • 6shr_system
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')