← back
CVE-2024-7202

Simopro Technology WinMatrix3 Web package - SQL Injection

CVSS 9.8 CRITICALEPSS 0.7%CWE-89
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.8EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
29 Jul 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →