SQL Injection Vulnerability in Weaver Ecology by Weaver
CVE-2024-48072
9.8CRITICAL
What is CVE-2024-48072?
A SQL injection vulnerability has been identified in Weaver Ecology version 9.*, allowing attackers to manipulate database queries via crafted input to the /mobilemode/Action.jsp endpoint. Specifically, an unauthorized user could exploit this by sending malicious values to the searchField, fromTable, whereClause, triggerCondition, and fieldValue parameters. This could lead to unauthorized access to sensitive data or system compromise, emphasizing the need for immediate mitigation measures.
