216.73.217.22

CVE-2024-42844

· Published 06/03/2025 15:15 · Modified 06/03/2025 17:15

Labels: CVE-2024-42844 2025-03-06CVE-2024-42844CWE-89[email protected]

Essential information

Published
06/03/2025 15:15
Modified
06/03/2025 17:15
Author
Creator
CVSS
8.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References