CVE ID | CVE-2024-6527 |
Publication date | 09 July 2024 |
Vendor | Jan Syski |
Product | MegaBIP |
Vulnerable versions | All through 5.13 |
Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
Report source | Own research |
Description
During its own research, CERT Polska has found another vulnerability in MegaBIP software and participated in coordination of its disclosure.
SQL Injection vulnerability CVE-2024-6527 in parameter "w" handled in file "druk.php" in MegaBIP software allows an unauthorized attacker to disclose the content of the database and obtain administrator's token to modify the content of pages.
This issue affects MegaBIP software versions through 5.13.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.