CVE-2024-51165
10.12.2024, 20:15
SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.
Vendor | Product | Version |
---|---|---|
ketr | jepaas | 7.2.8 |
𝑥
= Vulnerable software versions