PoC Index

CVE-2024-44349

CRITICAL 9.8EPSS 5.8%

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
5.78% chance of exploitation in the next 30 days, 93th percentile
Nuclei
critical · CWE-89
Published
2024-10-08
Updated
2024-10-10

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related