CVE-2024-26264

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
15/02/2024
Last modified:
23/01/2025

Description

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ebmtech:risweb:*:*:*:*:*:*:*:* 1.0 (including) 3.0 (excluding)