PT-2024-39969 · Newtype · Flowmaster Bpm Plus

Published

2024-10-14

·

Updated

2024-10-19

·

CVE-2024-9971

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FlowMaster BPM Plus from NewType (affected versions not specified)
Description The specific query functionality in the FlowMaster BPM Plus does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents. This issue can be exploited by attackers to access, alter, or remove database data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9971

Affected Products

Flowmaster Bpm Plus