TAI Smart Factory SQL Injection Vulnerability
CVE-2024-9925
9.8CRITICAL
What is CVE-2024-9925?
An SQL injection vulnerability has been identified in TAI Smart Factory's QPLANT SF version 1.0. This vulnerability permits a remote attacker to exploit the 'email' parameter within the 'RequestPasswordChange' endpoint by sending a carefully crafted SQL query. Successful exploitation could enable the attacker to retrieve sensitive information stored in the database, potentially compromising system integrity and confidentiality.
Affected Version(s)
QPLANT SF 1.0