Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker.
This issue was fixed in 18.1.376.37 version of the software.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker. This issue was fixed in 18.1.376.37 version of the software. | |
| Title | SQL Injection in Streamsoft Prestiż | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published: 2025-03-28T12:54:11.472Z
Updated: 2025-03-28T13:41:20.694Z
Reserved: 2024-11-20T18:47:35.492Z
Link: CVE-2024-11504
Updated: 2025-03-28T13:41:16.370Z
Status : Awaiting Analysis
Published: 2025-03-28T13:15:39.663
Modified: 2025-03-28T18:11:40.180
Link: CVE-2024-11504
No data.