CVE-2024-7732
14.08.2024, 07:15
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
Vendor | Product | Version |
---|---|---|
secom | dr.id_attendance_system | 𝑥 < 3.5.0.0.0.5 |
𝑥
= Vulnerable software versions