Siempelkamp: SQL injection due to improper handling of HTTP request input data
Vulnerability Description
A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-8308
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Johannes Lauinger of SySS GmbH
- Fidelis Abt of SySS GmbH
Affected Vendor
Siempelkamp
View all reports →