CVE-2024-44903
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 89
Summary
CVE-2024-44903 is a newly identified vulnerability affecting the SirsiDynix Horizon Information Portal (IPAC20) version 3.25_9382. The issue involves SQL Injection, which can be exploited through the ipac.jsp file in a SELECT statement located within the uri= variable of the full= inner variable. Although the vulnerability has been identified, a patch is now available from the vendor to mitigate the risk. It is crucial for system administrators to apply the patch promptly to prevent potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.