SQL Injection vulnerability in OpenGnsys
Vulnerability Description
SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to inject malicious SQL code into login page to bypass it or even retrieve all the information stored in the database.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3704
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Pedro Gabaldón Julá
- Javier Medina Munuera
- Antonio José Gálvez Sánchez
References
More from OpenGnsys
View All →Affected Vendor
OpenGnsys
View all reports →