Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Contact the vendor to install the patch or update to version 6.0 or later.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50261 | AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content. |
Tue, 15 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Esi Technology
Esi Technology aim Line Marketing Platform |
|
| CPEs | cpe:2.3:a:esi_technology:aim_line_marketing_platform:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Esi Technology
Esi Technology aim Line Marketing Platform |
|
| Metrics |
ssvc
|
Tue, 15 Oct 2024 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content. | |
| Title | ESi Technology AIM LINE Marketing Platform - SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-15T13:50:03.749Z
Reserved: 2024-10-15T06:58:01.120Z
Link: CVE-2024-9982
Updated: 2024-10-15T13:49:54.205Z
Status : Deferred
Published: 2024-10-15T08:15:03.603
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-9982
No data.
OpenCVE Enrichment
No data.
EUVD