Back

CRITICAL

Simopro Technology WinMatrix3 Web package - SQL Injection

Published Jul 29, 2024

Description

The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

Affected products

Remediation

Vendor solution

Update WinMatrix3 Web package to 1.2.35.3 or later version.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Jul 29, 2024
Updated Aug 1, 2024
Reserved Jul 29, 2024
CISA Vulnrichment
Updated Jul 29, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a