Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been resolved by the ATISolutions team in version 2.15.5.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48985 | SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information stored in the database. |
Mon, 26 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ciges
Ciges cigesv2 |
|
| CPEs | cpe:2.3:a:ciges:cigesv2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ciges
Ciges cigesv2 |
|
| Metrics |
ssvc
|
Mon, 26 Aug 2024 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to the /modules/ajaxServiciosCentro.php point in the idCentro parameter and retrieve all the information stored in the database. | |
| Title | SQL injection vulnerability in CIGESv2 system | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-26T15:07:44.572Z
Reserved: 2024-08-26T06:42:23.038Z
Link: CVE-2024-8161
Updated: 2024-08-26T15:06:50.918Z
Status : Deferred
Published: 2024-08-26T09:15:04.963
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-8161
No data.
OpenCVE Enrichment
No data.
EUVD