« Volver al listado

CVE-2024-28145

Estado: AplazadaMedia (5.9)—

An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-28145",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-28145",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-13T16:16:12.359376Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.9,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "affectedData": [
        {
          "vendor": "Image Access GmbH",
          "product": "Scan2Net",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.40",
                  "status": "unaffected"
                }
              ],
              "version": "0",
              "lessThan": "7.40",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-12-12T14:15:22.467",
  "references": [
    {
      "url": "https://r.sec-consult.com/imageaccess",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
    },
    {
      "url": "https://www.imageaccess.de/?page=SupportPortal&lang=en",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Dec/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter \"field\" with the UNION keyword."
    },
    {
      "lang": "es",
      "value": "Un atacante no autenticado puede realizar una inyección SQL accediendo al archivo /class/dbconnect.php y suministrando parámetros GET maliciosos. Los parámetros HTTP GET search, table, field y value son vulnerables. Por ejemplo, se puede realizar una inyección SQL en el parámetro \"field\" con la palabra clave UNION."
    }
  ],
  "lastModified": "2026-06-17T07:21:04.810",
  "sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}