PT-2024-22384 · Bm Soft · Bmplanning

Published

2024-08-02

·

Updated

2024-09-11

·

CVE-2024-28298

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BM SOFT BMPlanning version 1.0.0.1
Description The issue allows authenticated users to execute arbitrary SQL commands via parameters such as SEC IDF, LIE IDF, PLANF IDF, CLI IDF, DOS IDF, and possibly others to the "/BMServerR.dll/BMRest" API endpoint.
Recommendations For BM SOFT BMPlanning version 1.0.0.1, consider restricting access to the vulnerable API endpoint "/BMServerR.dll/BMRest" and avoid using the parameters SEC IDF, LIE IDF, PLANF IDF, CLI IDF, DOS IDF until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-28298

Affected Products

Bmplanning