CVE-2024-28298

SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly other parameters to /BMServerR.dll/BMRest.
Configurations

Configuration 1 (hide)

cpe:2.3:a:e-bmsoft:bmplanning:1.0.0.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-02 19:16

Updated : 2024-09-11 14:54


NVD link : CVE-2024-28298

Mitre link : CVE-2024-28298

CVE.ORG link : CVE-2024-28298


JSON object : View

Products Affected

e-bmsoft

  • bmplanning
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')