go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

TEAMPLUS TECHNOLOGY Team+ - SQL Injection

TVN ID TVN-202410001
CVE ID CVE-2024-9921
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products Team+ v13.5.x
Description The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.
Solution Update to version v14.0.0 or later.
Credit Huding (DEVCORE)
Public Date 2024-10-14
Top