The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Oct 2024 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Newtype
Newtype flowmaster Bpm Plus |
|
CPEs | cpe:2.3:a:newtype:flowmaster_bpm_plus:*:*:*:*:*:*:*:* | |
Vendors & Products |
Newtype
Newtype flowmaster Bpm Plus |
Tue, 15 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
New Type
New Type flowmaster Bpm Plus |
|
CPEs | cpe:2.3:a:new_type:flowmaster_bpm_plus:*:*:*:*:*:*:*:* | |
Vendors & Products |
New Type
New Type flowmaster Bpm Plus |
|
Metrics |
ssvc
|
Tue, 15 Oct 2024 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents. | |
Title | NewType FlowMaster BPM Plus - SQL Injection | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-15T14:05:33.351Z
Reserved: 2024-10-15T01:57:24.052Z
Link: CVE-2024-9971

Updated: 2024-10-15T14:05:28.315Z

Status : Analyzed
Published: 2024-10-15T04:15:05.080
Modified: 2024-10-17T20:34:30.257
Link: CVE-2024-9971

No data.