CVE-2024-24256
15.02.2024, 08:15
SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in the saveMove.jsp in the hr_position directory.
| Vendor | Product | Version |
|---|---|---|
| yonyou | yonyou | 𝑥 ≤ 9.0 |
𝑥
= Vulnerable software versions