EBM Technologies Uniweb/SoliPACS WebServer - SQL Injection
Vulnerability Description
EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and deleting database records, as well as executing system commands. Attackers may even leverage the dbo privilege in the database for privilege escalation, elevating their privileges to administrator .
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-26262
Credits & Attribution
No credits recorded in the NVD database.
More from EBM Technologies
View All →Affected Vendor
EBM Technologies
View all reports →