PT-2024-21317 · Ebm Technologies · Ebm Technologies Risweb

Published

2024-02-14

·

Updated

2024-02-15

·

CVE-2024-26264

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EBM Technologies RISWEB (affected versions not specified)
Description The issue concerns a specific query function parameter in EBM Technologies RISWEB that does not properly restrict user input. This feature page is accessible without login, allowing remote attackers to inject SQL commands without authentication. As a result, attackers can read, modify, and delete database records.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-26264

Affected Products

Ebm Technologies Risweb