Vulnerability Description
SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.artresilia.com/cve-2024-44903-sql-injection-vulnerability-in-horizon
- https://www.artresilia.com/cve-2024-44903-sql-injection-vulnerability-in-horizon
FAQ
What is CVE-2024-44903?
CVE-2024-44903 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a pa...
How severe is CVE-2024-44903?
CVE-2024-44903 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-44903?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.