CVE-2024-49666
CVSS 3.1 Score 8.5 of 10 (high)
Details
Published Jan 21, 2025
CWE ID 89
Summary
CVE-2024-49666 is a newly disclosed SQL Injection vulnerability affecting the ARPrice software, from an unknown version up to 4.0.3. The vulnerability stems from the improper neutralization of special elements in SQL commands, enabling attackers to inject malicious SQL statements and potentially gain unauthorized access to sensitive data or execute unintended operations on the affected system. This issue can lead to significant security risks and should be addressed promptly through the application of available patches or updates from the vendor.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.