CVE-2024-7202

The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simopro_technology:winmatrix3:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-07-29 04:15

Updated : 2024-11-21 09:51


NVD link : CVE-2024-7202

Mitre link : CVE-2024-7202

CVE.ORG link : CVE-2024-7202


JSON object : View

Products Affected

simopro_technology

  • winmatrix3
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')