← back
CVE-2024-8329

Gether Technology 6SHR System - SQL Injection

CVSS 8.8 HIGHEPSS 0.6%CWE-89
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
30 Aug 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H