CVE-2024-11020

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 11, 2024
Updated: Nov 12, 2024
CWE ID 89

Summary

CVE-2024-11020 is a newly disclosed vulnerability affecting Webopac, a software product provided by Grand Vice Info. This issue permits unauthenticated attackers to execute SQL injection attacks, enabling them to read, modify, and delete database contents remotely. This vulnerability poses a significant risk as it bypasses authentication requirements, allowing malicious actors to access sensitive information or make unauthorized changes to data stored in the affected database. Successful exploitation could lead to data breaches or system compromise. Organizations using Webopac are strongly advised to apply the available patch as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share