CVE-2024-7801
PoC —CVSS 4.0
6.3 medium
EPSS
<1%p56
Published
()
Modified
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Microchip TimeProvider 4100 (Data plot modules) allows SQL Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
- Vendors
- microchip
- Products
- timeprovider 4100 firmware
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:U/V:C/RE:M/U:Amber
In the news0 stories
No ingested article mentions this CVE yet.