CVE-2024-6527

SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disclose the contents of the database and obtain administrator's token to modify the content of pages.  This issue affects MegaBIP software versions through 5.13.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-07-09 14:15

Updated : 2024-07-09 18:19


NVD link : CVE-2024-6527

Mitre link : CVE-2024-6527

CVE.ORG link : CVE-2024-6527


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')