CVE-2024-41512

A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:4pace:cadclick:1.11.0:*:*:*:*:*:*:*

History

02 Jun 2025, 17:40

Type Values Removed Values Added
CPE cpe:2.3:a:4pace:cadclick:1.11.0:*:*:*:*:*:*:*
First Time 4pace
4pace cadclick
References () http://cadclick.de/ - () http://cadclick.de/ - Product
References () http://kimweb.de/ - () http://kimweb.de/ - Product
References () https://piuswalter.de/blog/multiple-critical-vulnerabilities-in-cadclick/ - () https://piuswalter.de/blog/multiple-critical-vulnerabilities-in-cadclick/ - Exploit, Third Party Advisory

04 Oct 2024, 21:15

Type Values Removed Values Added
References
  • () http://cadclick.de/ -
  • () http://kimweb.de/ -

04 Oct 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 18:15

Updated : 2025-06-02 17:40


NVD link : CVE-2024-41512

Mitre link : CVE-2024-41512


JSON object : View

Products Affected

4pace

  • cadclick
CWE

No CWE.