CVE-2024-25469: SQL Injection
SQL Injection vulnerability in CRMEB crmebjava v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the api/front/store/list component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25469?
CVE-2024-25469 has been classified as a critical severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2024-25469?
To fix CVE-2024-25469, update CRMEB crmeb_java to version 1.3.5 or newer to mitigate the SQL injection vulnerability.
Who is affected by CVE-2024-25469?
CVE-2024-25469 affects all versions of CRMEB crmeb_java up to and including version 1.3.4.
What kind of attack does CVE-2024-25469 enable?
CVE-2024-25469 enables remote attackers to perform SQL injection attacks, potentially allowing them to access sensitive information.
What parameters are involved in CVE-2024-25469?
CVE-2024-25469 specifically involves the latitude and longitude parameters in the api/front/store/list component.