PT-2024-33123 · Mrbs · Mrbs

Zo

·

Published

2024-10-28

·

Updated

2024-10-30

·

CVE-2024-48465

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MRBS version 1.5.0
Description The issue is related to an SQL injection vulnerability found in the edit entry handler.php file, specifically affecting the rooms%5B%5D parameter.
Recommendations For MRBS version 1.5.0, avoid using the rooms%5B%5D parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-48465

Affected Products

Mrbs