CVE-2024-50323

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 89

Summary

CVE-2024-50323 is a newly disclosed SQL injection vulnerability in Ivanti Endpoint Manager. This issue, affecting versions before the November 2024 Security Update and 2022 SU6, permits a local, unauthenticated attacker to execute arbitrary code. Interaction from a user is required for the exploitation of this vulnerability. This SQL injection flaw poses a significant risk, emphasizing the importance of applying the respective security updates promptly to mitigate potential threats.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share