CVE-2024-9982
EUVD-2024-5026115.10.2024, 08:15
AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| esi_technology | aim_line_marketing_platform | 3.3 ≤ 𝑥 ≤ 5.8.4 | ADP |