SQL Injection Vulnerability in Streamsoft Prestiż
CVE-2024-11504

8.6HIGH

Key Information:

Vendor

Streamsoft

Vendor
CVE Published:
28 March 2025

What is CVE-2024-11504?

Input fields in Streamsoft Prestiż are inadequately sanitized, creating a potential SQL injection risk. This vulnerability could be exploited by authenticated remote attackers to manipulate or extract sensitive database information. It is crucial for users of Streamsoft Prestiż to update to version 18.1.376.37 or later to mitigate this security threat.

Affected Version(s)

Streamsoft Prestiż 0 < 18.1.376.37

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Dąbkowski
.