CVE-2024-53544
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 24, 2025
Updated: Feb 25, 2025
CWE ID 89
Summary
CVE-2024-53544: A SQL injection vulnerability has been identified in NovaCHRON Zeitsysteme GmbH & Co. KG's Smart Time Plus version 8.x to 8.6. The issue lies in the getCookieNames method found in the smarttimeplus/MySQLConnection endpoint, enabling attackers to inject malicious SQL queries and potentially gain unauthorized access to sensitive data. This vulnerability poses a significant risk and necessitates immediate patching to prevent potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share