SQL Injection Vulnerability in Bentley Systems ProjectWise Integration Server
CVE-2024-53007

6.4MEDIUM

Key Information:

Vendor
Bentley
Vendor
CVE Published:
31 January 2025

Summary

A vulnerability in Bentley Systems ProjectWise Integration Server allows authenticated users to execute unintended SQL queries through an API call. This flaw may lead to unauthorized data exposure and potential manipulation of the database, highlighting the importance of securing API endpoints and validating user inputs.

Affected Version(s)

ProjectWise Integration Server 0 < 10.00.03.288

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.