PT-2025-7798 · Novachron Zeitsysteme Gmbh & Co. Kg · Smart Time Plus

Secure77

·

Published

2025-02-24

·

Updated

2025-02-25

·

CVE-2024-53543

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus versions 8.x through 8.6
Description The issue is related to a SQL injection vulnerability. It can be exploited via the addProject method in the "smarttimeplus/MySQLConnection" endpoint.
Recommendations For versions 8.x through 8.6, consider restricting access to the "smarttimeplus/MySQLConnection" endpoint until a patch is available. As a temporary workaround, avoid using the addProject method in the affected endpoint until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-53543

Affected Products

Smart Time Plus