44 lines
1.2 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-6160",
"sourceIdentifier": "cvd@cert.pl",
"published": "2024-06-24T10:15:10.277",
"lastModified": "2024-06-24T10:15:10.277",
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session cookies or modify the content of pages.\u00a0This issue affects MegaBIP software versions through 5.12.1."
}
],
"metrics": {},
"weaknesses": [
{
"source": "cvd@cert.pl",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://cert.pl/en/posts/2024/06/CVE-2024-6160/",
"source": "cvd@cert.pl"
},
{
"url": "https://cert.pl/posts/2024/06/CVE-2024-6160/",
"source": "cvd@cert.pl"
},
{
"url": "https://megabip.pl/",
"source": "cvd@cert.pl"
},
{
"url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej",
"source": "cvd@cert.pl"
}
]
}