CVE-2024-13955
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
22/05/2025
Last modified:
23/05/2025
Description
2nd Order SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if administrator credentials become compromised.This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
Base Score 3.x
8.80
Severity 3.x
HIGH