PT-2024-27368 · Tianwell · Tianwell Fire Intelligent Command Platform

Scausoft

·

Published

2024-04-13

·

Updated

2024-06-04

·

CVE-2024-3720

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tianwell Fire Intelligent Command Platform version 1.1.1.1
Description A critical issue has been found in the Tianwell Fire Intelligent Command Platform. This issue affects the API Interface component, specifically the /mfsNotice/page file. The manipulation of the gsdwid argument leads to SQL injection. The attack can be initiated remotely.
Recommendations For Tianwell Fire Intelligent Command Platform version 1.1.1.1, consider restricting access to the vulnerable API Interface component, specifically the /mfsNotice/page file, to minimize the risk of exploitation. Avoid using the gsdwid argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3720

Affected Products

Tianwell Fire Intelligent Command Platform