PT-2024-20983 · Ruvaroa · Ruvaroa

Mr-Xn

·

Published

2024-05-08

·

Updated

2024-07-03

·

CVE-2024-25522

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions RuvarOA versions 6.01 through 12.01
Description A SQL injection issue was discovered via the office missive id parameter at the "/WorkFlow/wf work form save.aspx" API endpoint. This allows attackers to inject malicious SQL.
Recommendations For versions 6.01 through 12.01, patch immediately and review code for proper input validation to prevent exploitation of the office missive id parameter in the "/WorkFlow/wf work form save.aspx" API endpoint. As a temporary workaround, consider restricting access to the vulnerable "/WorkFlow/wf work form save.aspx" endpoint until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-25522

Affected Products

Ruvaroa