Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 09 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-564

Thu, 09 Jan 2025 14:00:00 +0000

Type Values Removed Values Added
Description SQL Injection: Hibernate vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Weaknesses CWE-89

Thu, 21 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Teknogis Informatics
Teknogis Informatics close Circuit Vehicle Tracking Software
CPEs cpe:2.3:a:teknogis_informatics:close_circuit_vehicle_tracking_software:*:*:*:*:*:*:*:*
Vendors & Products Teknogis Informatics
Teknogis Informatics close Circuit Vehicle Tracking Software
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 Nov 2024 13:45:00 +0000

Type Values Removed Values Added
Description SQL Injection: Hibernate vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection.This issue affects Closed Circuit Vehicle Tracking Software: through 21.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title SQLi in Teknogis Informatics' Closed Circuit Vehicle Tracking Software
Weaknesses CWE-564
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published: 2024-11-21T13:21:59.843Z

Updated: 2025-01-09T16:31:58.161Z

Reserved: 2024-07-23T13:12:29.654Z

Link: CVE-2024-7026

cve-icon Vulnrichment

Updated: 2024-11-21T14:26:32.169Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-21T14:15:18.837

Modified: 2025-01-09T14:15:26.937

Link: CVE-2024-7026

cve-icon Redhat

No data.