VYPR
Unrated severityNVD Advisory· Published Aug 29, 2024· Updated Aug 29, 2024

Multiple vulnerabilities in SportsNET

CVE-2024-29723

Description

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/, parameter categoria;.

Affected products

2
  • SportsNET/SportsNETllm-create2 versions
    =4.0.1+ 1 more
    • (no CPE)range: =4.0.1
    • (no CPE)range: 4.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.