PT-2024-16392 · Safenet · Esafenet Cdg 5

0Menc

+1

·

Published

2024-10-31

·

Updated

2024-11-04

·

CVE-2024-10595

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ESAFENET CDG 5
Description A critical vulnerability was found in ESAFENET CDG 5, affecting the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/PublicDocInfoAjax.java. This vulnerability leads to SQL injection and can be exploited remotely. The exploit has been disclosed to the public, and the vendor was contacted but did not respond.
Recommendations Update to the latest patched version immediately to mitigate risks. As a temporary workaround, consider disabling the delFile/delDifferCourseList function until a patch is available. Restrict access to the /com/esafenet/servlet/ajax/PublicDocInfoAjax.java file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-10595

Affected Products

Esafenet Cdg 5