Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nguyen Hong Phuc

#29571of 53,633
8.8Total CVSS
Vulnerabilities · 1
PT-2025-3125
8.8
2025-01-08
Polaris Ft · Polaris Ft Intellect Core Banking · CVE-2024-55517
**Name of the Vulnerable Software and Affected Versions** Polaris FT Intellect Core Banking version 9.5 **Description** An issue was discovered in the Interllect Core Search, where input passed through the `groupType` parameter in "/SCGController" is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session. **Recommendations** For Polaris FT Intellect Core Banking version 9.5, as a temporary workaround, consider restricting access to the `/SCGController` endpoint or disabling the use of the `groupType` parameter until a patch is available. Avoid using the `groupType` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.