CVE-2024-48814

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 3, 2025
CWE ID 89

Summary

CVE-2024-48814 represents a significant SQL Injection vulnerability in the Silverpeas 6.4.1 platform. An attacker can exploit this flaw by manipulating the ViewType parameter in the findbywhereclause function, granting unauthorized access to sensitive data. This issue poses a serious risk, allowing remote adversaries to gain valuable information without proper authorization. Silverpeas users are advised to upgrade to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share