cve/2024/CVE-2024-44903.md
2025-09-29 16:08:36 +00:00

794 B

CVE-2024-44903

Description

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

POC

Reference

Github

No PoCs found on GitHub currently.