SQL Injection Vulnerabilities Affect SportsNet
CVE-2024-29726
9.8CRITICAL
What is CVE-2024-29726?
An SQL injection vulnerability has been identified in SportsNET, specifically in version 4.0.1. This security flaw enables an attacker to execute malicious SQL queries, potentially leading to unauthorized access, data retrieval, or even manipulation of the database. By targeting a specific endpoint with crafted SQL commands, an attacker could exploit this vulnerability to compromise sensitive information within the database. It is crucial for users of SportsNET to evaluate their systems for potential risks associated with this vulnerability and implement necessary security measures.
Affected Version(s)
SportsNET 4.0.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-sportsnet