CVE-2024-48072: SQL Injection
Weaver Ecology v9. was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&action=getFieldTriggerValue&searchField=&fromTable=HrmResourceManager&whereClause=1%3d1&triggerCondition=1&expression=%3d&fieldValue=1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48072?
CVE-2024-48072 has been classified as a high severity vulnerability due to its potential to allow unauthorized access to the database.
How do I fix CVE-2024-48072?
To fix CVE-2024-48072, it is recommended to validate and sanitize all user inputs to prevent SQL injection.
What software versions are affected by CVE-2024-48072?
CVE-2024-48072 affects Weaver Ecology versions 9.* and 8.0.
What type of vulnerability is CVE-2024-48072?
CVE-2024-48072 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL queries.
Can CVE-2024-48072 be exploited remotely?
Yes, CVE-2024-48072 can be exploited remotely, allowing attackers to compromise database integrity from a distant location.