VYPR
Unrated severityNVD Advisory· Published Aug 29, 2024· Updated Aug 29, 2024

Multiple vulnerabilities in SportsNET

CVE-2024-29727

Description

SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRemember/ , parameter send.

Affected products

2
  • SportsNET/SportsNETllm-fuzzy2 versions
    = 4.0.1+ 1 more
    • (no CPE)range: = 4.0.1
    • (no CPE)range: 4.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.