SQL Injection Vulnerability in HubBank by Unknown Vendor
CVE-2024-4309

8.1HIGH

Key Information:

Vendor

Unknown

Status
Vendor
CVE Published:
29 April 2024

What is CVE-2024-4309?

An SQL injection vulnerability has been identified in HubBank version 1.0.2, allowing attackers to execute malicious SQL queries via various endpoints. This flaw enables unauthorized access to sensitive data in the database by manipulating the 'id' parameter in requests. Attackers can potentially extract confidential information, posing significant risks to data integrity and privacy.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.