Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.

Project Subscriptions

Vendors Products
Webopac Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-33612 Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
Fixes

Solution

Update Webopac 6 to version 6.5.1 or later. Update Webopac 7 to version 7.2.3 or later.


Workaround

No workaround given by the vendor.

History

Mon, 11 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Vice
Vice webopac
CPEs cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
Vendors & Products Vice
Vice webopac
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 11 Nov 2024 07:30:00 +0000

Type Values Removed Values Added
Description Webopac from Grand Vice info has a SQL Injection vulnerability, allowing unauthenticated remote attacks to inject arbitrary SQL commands to read, modify, and delete database contents.
Title Grand Vice info Webopac7 - SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-11-11T16:03:11.895Z

Reserved: 2024-11-08T05:54:44.679Z

Link: CVE-2024-11020

cve-icon Vulnrichment

Updated: 2024-11-11T16:02:56.627Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-11T08:15:03.610

Modified: 2024-11-18T18:59:39.293

Link: CVE-2024-11020

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses