60 lines
2.1 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-8259",
"sourceIdentifier": "iletisim@usom.gov.tr",
"published": "2024-12-09T14:15:13.473",
"lastModified": "2024-12-13T08:15:05.017",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This issue affects NatraCar B2B Dealer Management Program: through 09.12.2024.\n\n\n\nNOTE: The vendor was contacted and it was learned that the product is not supported."
},
{
"lang": "es",
"value": "Vulnerabilidad de neutralizaci\u00f3n inadecuada de elementos especiales utilizados en un comando SQL (\"inyecci\u00f3n SQL\") en Eryaz Information Technologies NatraCar B2B Dealer Management Program permite la inyecci\u00f3n SQL. Este problema afecta al programa de gesti\u00f3n de distribuidores B2B de NatraCar hasta el 09.12.2024. NOTA: Se contact\u00f3 al proveedor y se supo que el producto no recibe soporte."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "iletisim@usom.gov.tr",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "iletisim@usom.gov.tr",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"references": [
{
"url": "https://www.usom.gov.tr/bildirim/tr-24-1881",
"source": "iletisim@usom.gov.tr"
}
]
}