PT-2024-32050 · Te Informatics · Nova Cms

Published

2024-10-10

·

Updated

2025-10-14

·

CVE-2024-4658

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions TE Informatics Nova CMS versions prior to 5.0
Description A SQL Injection vulnerability exists in TE Informatics Nova CMS due to a Hibernate flaw. This issue allows for SQL Injection, which can be exploited.
Recommendations For TE Informatics Nova CMS versions prior to 5.0, update to version 5.0 or later to resolve the issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-4658

Affected Products

Nova Cms