First published: Thu Oct 31 2024(Updated: )
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/PublicDocInfoAjax.java. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto SafeNet CDG | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10595 has been declared as critical due to its potential for SQL injection.
To fix CVE-2024-10595, update ESAFENET CDG to the latest version that addresses this vulnerability.
CVE-2024-10595 allows attackers to perform SQL injection attacks via the delFile/delDifferCourseList function.
CVE-2024-10595 affects ESAFENET CDG version 5.
As of the current date, there is no specific information confirming active exploitation of CVE-2024-10595.