VYPR
High severity8.1NVD Advisory· Published Mar 6, 2025· Updated Apr 15, 2026

CVE-2024-42844

CVE-2024-42844

Description

A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated SQL injection in EPICOR Prophet 21 up to 23.2.5232 allows remote attackers to execute arbitrary SQL commands via unsanitized input to obtain unauthorized data.

Vulnerability

Overview

CVE-2024-42844 is an authenticated SQL injection vulnerability in EPICOR Prophet 21 (P21) up to version 23.2.5232. The root cause is unsanitized user input fields that fail to properly neutralize special SQL elements, enabling an attacker to inject arbitrary SQL commands into queries executed by the application [1].

Exploitation

The attack vector is remote and requires prior authentication, meaning an attacker must have valid credentials to exploit the flaw. Once authenticated, the attacker supplies malicious SQL payloads via the vulnerable input fields, and the application processes them without adequate sanitization, leading to unauthorized database interaction [1].

Impact

Successful exploitation allows an authenticated remote attacker to execute arbitrary SQL commands against the backend database. This can result in the unauthorized retrieval, modification, or deletion of sensitive data, potentially compromising the confidentiality and integrity of the system [1].

Mitigation

EPICOR has released a fix in version 24.1.5358. Customers are advised to upgrade to this version or later. Additional details are available in EpicCare article KB0138127 [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.