First published: Mon Oct 14 2024(Updated: )
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.
Credit: twcert@cert.org.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Teamplus Team\+ Pro | >=13.5.0<14.0.0 |
Update to version v14.0.0 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.