ZeroHour

CVE-2024-26264

CVSS 3.1
9.8 critical
EPSS
<1%p56
Published
()
Modified
Description

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.

Vendors
ebmtech
Products
risweb
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.