FlexWater Corporate Water Management Vulnerable to SQL Injection
CVE-2024-0857
9.8CRITICAL
What is CVE-2024-0857?
An SQL Injection vulnerability exists in Universal Software Inc.'s FlexWater Corporate Water Management that allows attackers to inject malicious SQL queries. This flaw arises due to improper neutralization of special elements within SQL commands. Exploiting this vulnerability could enable unauthorized access to sensitive data, manipulation of database entries, and potential compromises of the entire database system. Users of FlexWater Corporate Water Management versions prior to 5.452.0 should prioritize applying security updates to mitigate this issue.
Affected Version(s)
FlexWater Corporate Water Management 0 < 5.452.0
