ZeroHour

CVE-2024-41512

PoC
CVSS 3.1
8.8 high
EPSS
<1%p50
Published
()
Modified
Description

A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" parameter.

Vendors
4pace
Products
cadclick
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.