VYPR
Unrated severityNVD Advisory· Published Aug 29, 2024· Updated Aug 29, 2024

Multiple vulnerabilities in SportsNET

CVE-2024-29725

Description

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/, parameter list.

Affected products

2
  • SportsNET/SportsNETllm-fuzzy2 versions
    =4.0.1+ 1 more
    • (no CPE)range: =4.0.1
    • (no CPE)range: 4.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.