PT-2024-39543 · Trtek · Trtek Software Distant Education Platform

Dogus Demirkiran

·

Published

2024-10-09

·

Updated

2025-10-14

·

CVE-2024-9286

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TRtek Software Distant Education Platform versions prior to 3.2024.11
Description The issue is related to Improper Neutralization of Special Elements used in an SQL Command, also known as SQL Injection, and Improper Input Validation vulnerability. This allows for SQL Injection and Parameter Injection, posing a serious cybersecurity risk.
Recommendations For versions prior to 3.2024.11, update to version 3.2024.11 or later to resolve the issue. As a temporary workaround, consider restricting input validation to minimize the risk of exploitation. Restrict access to sensitive database queries to minimize the risk of SQL Injection.

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-9286

Affected Products

Trtek Software Distant Education Platform