Description
A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.
Published: 2024-11-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-49589 A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.
History

Fri, 29 Nov 2024 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Siempelkamp
Siempelkamp umweltoffice
CPEs cpe:2.3:a:siempelkamp:umweltoffice:*:*:*:*:*:*:*:*
Vendors & Products Siempelkamp
Siempelkamp umweltoffice
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 Nov 2024 10:45:00 +0000

Type Values Removed Values Added
Description A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.
Title Siempelkamp: SQL injection due to improper handling of HTTP request input data
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Siempelkamp Umweltoffice
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2024-11-29T19:07:16.321Z

Reserved: 2024-08-29T13:20:48.703Z

Link: CVE-2024-8308

cve-icon Vulnrichment

Updated: 2024-11-29T19:06:53.130Z

cve-icon NVD

Status : Deferred

Published: 2024-11-28T11:15:54.697

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-8308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses