CVE-2024-12016

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 89

Summary

CVE-2024-12016 is a vulnerability affecting CM Informatics CM News, where SQL Injection is possible due to improper neutralization of special elements used in SQL commands. This issue, which is present in versions up to 6.0, could allow unauthorized access to sensitive data or even complete system takeover. Unfortunately, the vendor has confirmed that the product is no longer supported, leaving users at risk until an alternative solution can be implemented.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share