PT-2024-38370 · Forip Tecnologia · Forip Tecnologia Administração Pabx

Gabriel

·

Published

2024-08-04

·

Updated

2024-09-11

·

CVE-2024-7461

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ForIP Tecnologia Administração PABX versions 1.x
Description A critical issue affects some unknown functionality of the file /authMonitCallcenter of the component monitcallcenter. The manipulation of the user argument leads to SQL injection. This issue can be exploited remotely.
Recommendations For ForIP Tecnologia Administração PABX versions 1.x, consider restricting access to the /authMonitCallcenter file to minimize the risk of exploitation. Avoid using the user argument in the affected component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7461

Affected Products

Forip Tecnologia Administração Pabx