CVE-2024-10244
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 19, 2024
CWE ID 89
Summary
CVE-2024-10244 is a newly disclosed SQL Injection vulnerability affecting ISDO Software Web Software. The flaw, located before version 3.6, stems from the software's failure to properly neutralize special elements in SQL commands. An attacker could exploit this vulnerability to inject malicious SQL statements and gain unauthorized access to sensitive data, potentially leading to data breaches or system takeover. It is crucial for users running impacted versions to upgrade as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.