CVE-2024-42533
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 89
Summary
CVE-2024-42533 is a newly disclosed SQL injection vulnerability that affects the authentication module in Convivance StandVoice versions 4.5 to 6.2. Malicious actors can exploit this issue by injecting malicious SQL queries through the GEST_LOGIN parameter, allowing them to execute arbitrary code remotely. Successful exploitation of this vulnerability could result in unauthorized access to sensitive information or system takeover. It is recommended that users update their Convivance StandVoice installations as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.