Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54498 | SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable. |
Tue, 25 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Mar 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20): through 3.25_9382. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable. | SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable. |
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Tue, 25 Mar 2025 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20): through 3.25_9382. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-25T13:23:08.277Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44903
Updated: 2025-03-25T13:23:02.521Z
Status : Deferred
Published: 2025-03-25T06:15:39.790
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-44903
No data.
OpenCVE Enrichment
No data.
EUVD