Grand Vice info's Webopac vulnerable to SQL Injection
CVE-2024-11020

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
11 November 2024

What is CVE-2024-11020?

Webopac, developed by Grand Vice Info, contains a vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands through SQL Injection. This vulnerability can lead to unauthorized access to the underlying database, enabling attackers to read, modify, or delete critical data. Organizations using affected versions of Webopac should prioritize the application of security patches and implement additional protective measures to safeguard their database integrity.

Affected Version(s)

Webopac7 6 < 6.5.1

Webopac7 7 < 7.2.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.