CVE-2024-47487: SQL Injection
Published Oct 18, 2024
·Updated
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
Affected Software
1 affected component
Hikvision Hikcentral Professional>=2.0.0<2.6.1
Event History
Oct 18, 2024
CVE Published
via MITRE·08:32 AM
Data Sourced
via MITRE·08:32 AM
Description
Data Sourced
via NVD·09:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-47487?
CVE-2024-47487 has a high severity rating due to its potential for allowing authenticated users to execute arbitrary SQL queries.
2
How do I fix CVE-2024-47487?
To fix CVE-2024-47487, update HikCentral Professional to version 2.6.1 or later immediately.
3
Who is affected by CVE-2024-47487?
CVE-2024-47487 affects users of HikCentral Professional versions ranging from 2.0.0 to 2.6.1.
4
What kind of attacks can CVE-2024-47487 enable?
CVE-2024-47487 can enable SQL injection attacks that may lead to unauthorized data access or manipulation.
5
Is CVE-2024-47487 exploitable without authentication?
No, CVE-2024-47487 requires that the attacker is an authenticated user to exploit the vulnerability.