CVE-2024-50706

Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:uniguest:tripleplay:24.2:*:*:*:*:*:*:*
cpe:2.3:a:uniguest:tripleplay:*:*:*:*:*:*:*:*

History

28 May 2025, 17:26

Type Values Removed Values Added
First Time Uniguest
Uniguest tripleplay
CPE cpe:2.3:a:uniguest:tripleplay:24.2:*:*:*:*:*:*:*
cpe:2.3:a:uniguest:tripleplay:*:*:*:*:*:*:*:*
References () https://uniguest.com/cve-bulletins/ - () https://uniguest.com/cve-bulletins/ - Vendor Advisory
References () https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50706-Vulnerability-Summary.pdf - () https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50706-Vulnerability-Summary.pdf - Broken Link

17 Apr 2025, 18:15

Type Values Removed Values Added
Summary Unauthenticated SQL injection vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary SQL queries on the backend database. Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.

04 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 15:15

Updated : 2025-05-28 17:26


NVD link : CVE-2024-50706

Mitre link : CVE-2024-50706


JSON object : View

Products Affected

uniguest

  • tripleplay
CWE

No CWE.