VYPR
Unrated severityNVD Advisory· Published May 8, 2024· Updated Aug 1, 2024

CVE-2024-25524

CVE-2024-25524

Description

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the sys_file_storage_id parameter at /WorkPlan/WorkPlanAttachDownLoad.aspx.

Affected products

2
  • RuvarOA/RuvarOAdescription
  • RuvarOA/RuvarOAllm-create
    Range: v6.01, v12.01

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.