CVE-2024-41476

AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/card_detail.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:amttgroup:hibos:*:*:*:*:*:*:*:*

History

17 Oct 2025, 17:13

Type Values Removed Values Added
First Time Amttgroup hibos
CPE cpe:2.3:a:amttgroup:hotel_broadband_operating_system:*:*:*:*:*:*:*:* cpe:2.3:a:amttgroup:hibos:*:*:*:*:*:*:*:*

30 Sep 2025, 19:02

Type Values Removed Values Added
First Time Amttgroup hotel Broadband Operating System
Amttgroup
References () https://gist.github.com/lidy4x1/3314fbd82c3d72831c16f9c47a9bfb11 - () https://gist.github.com/lidy4x1/3314fbd82c3d72831c16f9c47a9bfb11 - Third Party Advisory
References () https://www.amttgroup.com/ - () https://www.amttgroup.com/ - Product
CPE cpe:2.3:a:amttgroup:hotel_broadband_operating_system:*:*:*:*:*:*:*:*

Information

Published : 2024-08-12 13:38

Updated : 2025-10-17 17:13


NVD link : CVE-2024-41476

Mitre link : CVE-2024-41476

CVE.ORG link : CVE-2024-41476


JSON object : View

Products Affected

amttgroup

  • hibos
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')