PT-2024-31827 · Baltic It · Baltic-It Topqw Webportal

Majid Lakhnati

+1

·

Published

2024-11-13

·

Updated

2024-11-15

·

CVE-2024-45875

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions baltic-it TOPqw Webportal versions 1.35.287.1 through 1.35.290
Description The create user function in the baltic-it TOPqw Webportal is vulnerable to SQL injection. This issue affects the /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser endpoint, where the username variable in the JSON object allows the manipulation of SQL queries.
Recommendations For versions 1.35.287.1 through 1.35.290, update to version 1.35.291 to resolve the issue. As a temporary workaround, consider restricting access to the /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser endpoint until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45875

Affected Products

Baltic-It Topqw Webportal