CVE-2024-11016
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Nov 11, 2024
Updated: Nov 14, 2024
CWE ID 89
Summary
CVE-2024-11016 is a newly disclosed SQL Injection vulnerability affecting Webopac, a software solution by Grand Vice Info. This issue permits unauthenticated remote attackers to inject malicious SQL commands, granting them the ability to read, modify, and delete sensitive data stored in the affected database. This vulnerability poses a significant threat, as it bypasses authentication requirements, increasing the risk of data breaches and potential system compromise.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.