PT-2024-38540 · Secom · Dr.Id Access Control System

Cyku Hong

·

Published

2024-08-14

·

Updated

2024-10-03

·

CVE-2024-7732

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dr.ID Access Control System from SECOM versions up to 3.6.2
Description The issue allows unauthenticated remote attackers to inject SQL commands, enabling them to read, modify, and delete database contents due to improper validation of a specific page parameter.
Recommendations For versions up to 3.6.2, patch immediately to mitigate risks. As a temporary workaround, consider restricting access to the vulnerable page parameter until a patch is available.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7732

Affected Products

Dr.Id Access Control System