go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

AguardNet Space Management System - SQL injection

TVN ID TVN-202407009
CVE ID CVE-2024-6743
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Space Management System before version 2024-04-09-3302.
Description AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Solution Update to 2024-04-09-3302 or later version.
Credit BrianLin(BAOHWA TRUST)
Public Date 2024-07-15
Top