CVE Published: 09/09/2024 |
CVE Updated: 09/09/2024 |
CVE Year: 2024 Source: Baxter |
Vendor: Baxter |
Product: Connex Health Portal Status : PUBLISHED
CVE-2024-6795 Description
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal\'s database.
An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content
and/or perform administrative operations including shutting down the database.
Metrics
CVSS Version: 3.1 |
Base Score: 10 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H