Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker.
This issue was fixed in 18.1.376.37 version of the software.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker. This issue was fixed in 18.1.376.37 version of the software. | |
| Title | SQL Injection in Streamsoft Prestiż | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2025-03-28T13:41:20.694Z
Reserved: 2024-11-20T18:47:35.492Z
Link: CVE-2024-11504
Updated: 2025-03-28T13:41:16.370Z
Status : Deferred
Published: 2025-03-28T13:15:39.663
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-11504
No data.
OpenCVE Enrichment
No data.