SQL Injection Vulnerability in Bentley Systems ProjectWise Integration Server
CVE-2024-53007
6.4MEDIUM
Key Information:
- Vendor
- Bentley
- Vendor
- CVE Published:
- 31 January 2025
Summary
A vulnerability in Bentley Systems ProjectWise Integration Server allows authenticated users to execute unintended SQL queries through an API call. This flaw may lead to unauthorized data exposure and potential manipulation of the database, highlighting the importance of securing API endpoints and validating user inputs.
Affected Version(s)
ProjectWise Integration Server 0 < 10.00.03.288
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved