← back
CVE-2024-1576

SQL Injection in MegaBIP

CVSS 9.3 CRITICALEPSS 0.6%CWE-89
SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:I/V:D/RE:M/U:Amber
Affected products
Jan Syski · MegaBIP

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →