CVE-2024-9982
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
15/10/2024
Last modified:
15/10/2024
Description
AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL