CVE-2024-8329
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: twcert@cert.org.tw (Secondary)
Description
6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.
Affected (1)
Products: 6shr System Project: 6shr System
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (2)
Timeline
No history available yet.