CVE Published: 18/07/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: TR-CERT |
Vendor: Universal Software Inc. |
Product: FlexWater Corporate Water Management Status : PUBLISHED
CVE-2024-0857 Description
Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection.This issue affects FlexWater Corporate Water Management: before 5.452.0.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H