SQL Injection Vulnerability in GetDIAE unListParameters
CVE-2024-23494
8.8HIGH
Summary
A SQL injection vulnerability exists in the GetDIAE_unListParameters component of the GetDIAE product by CISA. This vulnerability allows attackers to execute arbitrary SQL queries against the database, potentially leading to unauthorized access to sensitive information or modification of data. Proper validation of user input is critical to mitigate this risk. Organizations using affected versions should prioritize applying security measures to safeguard their systems from exploitation.
Affected Version(s)
DIAEnergie 0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl reported these vulnerabilities to CISA.