PT-2024-20568 · Mha Sistemas · Mha Sistemas Armhazena

João Silveira

+2

·

Published

2024-03-14

·

Updated

2024-05-17

·

CVE-2024-2480

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MHA Sistemas arMHAzena version 9.6.0.0
Description A critical vulnerability was found in the Executa Page component, affecting unknown code. The manipulation of the Companhia/Planta/Agente de/Agente até argument leads to SQL injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For version 9.6.0.0, consider restricting access to the Executa Page component until a patch is available. As a temporary workaround, avoid using the Companhia/Planta/Agente de/Agente até argument in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2480

Affected Products

Mha Sistemas Armhazena