PT-2024-36639 · Unknown · Serviceonline Service

Mika

·

Published

2024-12-16

·

Updated

2024-12-16

·

CVE-2024-55986

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions serviceonline Service versions n/a through 1.0.4
Description The issue is related to an 'SQL Injection' vulnerability, specifically improper neutralization of special elements used in an SQL command, allowing Blind SQL Injection. This problem affects the serviceonline Service, enabling potential unauthorized access.
Recommendations For versions n/a through 1.0.4, update to a version that includes a fix for this issue to prevent potential cyber threats. As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-55986

Affected Products

Serviceonline Service