CVE-2024-30801: SQL Injection
Published May 10, 2024
·Updated
SQL Injection vulnerability in Cloud based customer service management platform v.1.0.0 allows a local attacker to execute arbitrary code via a crafted payload to Login.asp component.
Affected Software
1 affected component
Cloud customer service management platform=1.0.0
Event History
May 10, 2024
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
Description
May 14, 2024
Data Sourced
via NVD·03:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-30801?
CVE-2024-30801 is considered a critical severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2024-30801?
To fix CVE-2024-30801, update the Cloud based customer service management platform to a patched version that resolves the SQL Injection vulnerability.
3
Who is affected by CVE-2024-30801?
CVE-2024-30801 affects users running version 1.0.0 of the Cloud based customer service management platform.
4
What type of vulnerability is CVE-2024-30801?
CVE-2024-30801 is an SQL Injection vulnerability that allows local attackers to execute arbitrary code.
5
What component is vulnerable in CVE-2024-30801?
The vulnerable component in CVE-2024-30801 is the Login.asp page of the affected software.