CVE-2024-1576

SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.
Configurations

Configuration 1 (hide)

cpe:2.3:a:megabip:megabip:*:*:*:*:*:*:*:*

History

14 Aug 2024, 13:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-89
First Time Megabip
Megabip megabip
CPE cpe:2.3:a:megabip:megabip:*:*:*:*:*:*:*:*
References () https://cert.pl/posts/2024/06/CVE-2024-1576/ - () https://cert.pl/posts/2024/06/CVE-2024-1576/ - Third Party Advisory
References () https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej - () https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej - Press/Media Coverage
References () https://cert.pl/en/posts/2024/06/CVE-2024-1576/ - () https://cert.pl/en/posts/2024/06/CVE-2024-1576/ - Third Party Advisory
References () https://megabip.pl/ - () https://megabip.pl/ - Product

12 Jun 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-12 14:15

Updated : 2024-08-14 13:55


NVD link : CVE-2024-1576

Mitre link : CVE-2024-1576


JSON object : View

Products Affected

megabip

  • megabip
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')