CVE-2024-44349
63Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 9.8epss 5.8%
from disclosure to weapon0 days
Published on NVDOct 8
1st PoCJul 26
exploitation probability
5.8%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/apublic PoCs found — 1
githubgithub.com/AndreaF17/PoC-CVE-2024-44349★ 1⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.