CVE-2024-54820
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 24, 2025
CWE ID 89
Summary
CVE-2024-54820 is a newly discovered SQL injection vulnerability affecting the XOne Web Monitor v02.10.2024.530 framework 1.0.4.9. The login page of this software contains the flaw, which enables attackers to inject malicious SQL queries. By manipulating input data, attackers can extract all usernames and passwords from the underlying database, posing a significant security risk. This issue underscores the importance of regularly updating software and implementing robust input validation techniques to prevent such vulnerabilities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share