CVE-2024-28145
Estado: AplazadaMedia (5.9)—
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
CWE
- CWE-89
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-28145",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-28145",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-12-13T16:16:12.359376Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 2.5
}
]
},
"affected": [
{
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"affectedData": [
{
"vendor": "Image Access GmbH",
"product": "Scan2Net",
"versions": [
{
"status": "affected",
"changes": [
{
"at": "7.40",
"status": "unaffected"
}
],
"version": "0",
"lessThan": "7.40",
"versionType": "custom"
}
],
"defaultStatus": "affected"
}
]
}
],
"published": "2024-12-12T14:15:22.467",
"references": [
{
"url": "https://r.sec-consult.com/imageaccess",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
},
{
"url": "https://www.imageaccess.de/?page=SupportPortal&lang=en",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf"
},
{
"url": "http://seclists.org/fulldisclosure/2024/Dec/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "551230f0-3615-47bd-b7cc-93e92e730bbf",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter \"field\" with the UNION keyword."
},
{
"lang": "es",
"value": "Un atacante no autenticado puede realizar una inyección SQL accediendo al archivo /class/dbconnect.php y suministrando parámetros GET maliciosos. Los parámetros HTTP GET search, table, field y value son vulnerables. Por ejemplo, se puede realizar una inyección SQL en el parámetro \"field\" con la palabra clave UNION."
}
],
"lastModified": "2026-06-17T07:21:04.810",
"sourceIdentifier": "551230f0-3615-47bd-b7cc-93e92e730bbf"
}