PT-2025-13510 · Streamsoft · Streamsoft Prestiż

Kamil Dąbkowski

·

Published

2025-03-28

·

Updated

2025-03-28

·

CVE-2024-11504

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Streamsoft Prestiż versions prior to 18.1.376.37
Description The issue is related to improper sanitization of input from multiple fields in Streamsoft Prestiż, leading to an SQL injection vulnerability. This vulnerability might be exploited by an authenticated remote attacker.
Recommendations For versions prior to 18.1.376.37, update to version 18.1.376.37 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11504

Affected Products

Streamsoft Prestiż