SQL Injection Vulnerability Affects HikCentral Professional
CVE-2024-47487

7.2HIGH

Key Information:

Vendor

Hikvision

Vendor
CVE Published:
18 October 2024

What is CVE-2024-47487?

A SQL injection vulnerability exists in certain versions of HikCentral Professional, developed by Hikvision. This flaw allows authenticated users to manipulate SQL queries, potentially leading to unauthorized data access or modification. Such an exploitation poses a significant risk to the security and integrity of database-driven applications, making it crucial for affected users to apply security updates and patches as they become available.

Affected Version(s)

HikCentral Professional Versions between V2.0.0 and V2.6.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manh Doan Duc
.