Vulnerability Description
SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/modules/api/model/cmdb/isys_api_model_cmdb_objects_by_relation.class.php and retrieve all the information stored in the database.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| I-Doit | I-Doit | 28 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-syneThird Party Advisory
FAQ
What is CVE-2024-8749?
CVE-2024-8749 is a vulnerability with a CVSS score of 8.8 (HIGH). SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in /var/www/html/src/classes/modules/api/model/cmd...
How severe is CVE-2024-8749?
CVE-2024-8749 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-8749?
Check the references section above for vendor advisories and patch information. Affected products include: I-Doit I-Doit.