PT-2024-39224 · Unknown · I-Doit Pro

Adriá Bonilla Martin

+1

·

Published

2024-09-12

·

Updated

2024-09-18

·

CVE-2024-8749

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: idoit pro version 28
Description: The issue is a SQL injection vulnerability that could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/modules/api/model/cmdb/isys api model cmdb objects by relation.class.php and retrieve all the information stored in the database. This vulnerability could be exploited remotely.
Recommendations: For idoit pro version 28, update the software to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the vulnerable API endpoint /var/www/html/src/classes/modules/api/model/cmdb/isys api model cmdb objects by relation.class.php to minimize the risk of exploitation. Avoid using the ID parameter in the affected API endpoint until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-8749

Affected Products

I-Doit Pro