CVE-2024-28298: SQL Injection
SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SECIDF, LIEIDF, PLANFIDF, CLIIDF, DOSIDF, and possibly other parameters to /BMServerR.dll/BMRest.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28298?
CVE-2024-28298 is considered a critical SQL injection vulnerability that allows authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2024-28298?
To mitigate CVE-2024-28298, update the BM SOFT BMPlanning software to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-28298?
CVE-2024-28298 impacts users of the BM SOFT BMPlanning version 1.0.0.1.
What types of attacks can be performed using CVE-2024-28298?
Exploiting CVE-2024-28298 allows attackers to perform unauthorized actions such as reading, modifying, or deleting database records.
Is authentication required to exploit CVE-2024-28298?
Yes, CVE-2024-28298 requires that an attacker is an authenticated user to exploit the SQL injection vulnerability.