PT-2024-36624 · Unknown · Etemplates

João Pedro S Alcântara

·

Published

2024-12-16

·

Updated

2025-01-07

·

CVE-2024-55972

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions eTemplates versions 0.2.1 and earlier
Description The issue is related to the improper neutralization of special elements used in an SQL command, allowing SQL injection. This problem can be exploited to inject SQL code, potentially leading to unauthorized access or data manipulation.
Recommendations For versions 0.2.1 and earlier, ensure your eTemplates version is updated to a version after 0.2.1 to stay protected. As a temporary workaround, consider restricting access to vulnerable SQL commands or parameters until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-55972

Affected Products

Etemplates