The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cyber.wtf/2024/11/11/topqw-webportal-cves/ |
|
History
Thu, 21 Nov 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 13 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The create user function in baltic-it TOPqw Webportal 1.35.287.1 (fixed in version1.35.291), in /Apps/TOPqw/BenutzerManagement.aspx/SaveNewUser, is vulnerable to SQL injection. The JSON object username allows the manipulation of SQL queries. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-13T00:00:00
Updated: 2024-11-21T21:51:11.704Z
Reserved: 2024-09-11T00:00:00
Link: CVE-2024-45875
Updated: 2024-11-21T21:50:58.639Z
Status : Awaiting Analysis
Published: 2024-11-13T21:15:28.843
Modified: 2024-11-21T22:15:07.780
Link: CVE-2024-45875
No data.