CVE-2024-48814
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 3, 2025
CWE ID 89
Summary
CVE-2024-48814 represents a significant SQL Injection vulnerability in the Silverpeas 6.4.1 platform. An attacker can exploit this flaw by manipulating the ViewType parameter in the findbywhereclause function, granting unauthorized access to sensitive data. This issue poses a serious risk, allowing remote adversaries to gain valuable information without proper authorization. Silverpeas users are advised to upgrade to a patched version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.