Today > 5 Critical | 25 High | 21 Medium vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-11837

Dec. 13, 2024, 6:15 a.m.

Product(s) Impacted

PlexTrac

  • 1.61.3
  • before 2.8.1

Description

Improper Neutralization of Special Elements used in an N1QL Command ('N1QL Injection') vulnerability in PlexTrac  allows N1QL Injection.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

Weaknesses

CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component.

CWE ID: 89

Date

Published: Dec. 13, 2024, 6:15 a.m.

Last Modified: Dec. 13, 2024, 6:15 a.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

5fea7123-217b-4b2d-ada8-8892719b43cd

References

https://docs.plextrac.com/ 5fea7123-217b-4b2d-ada8-8892719b43cd