← Back

CVE-2024-9971

nvd nist
Published: Oct 15, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: twcert@cert.org.tw (Secondary)

Description

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

Affected (1)

1 product
Flowmaster Bpm Plus
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.3.1

References (2)

Source: twcert@cert.org.tw
Third Party Advisory
Source: twcert@cert.org.tw
Third Party Advisory

Timeline

No history available yet.