CRITICAL
ChanGate Property Management System - SQL Injection
Published Oct 15, 2024
9.8
CRITICALCVSS 3.1
EPSS 0.68%
Description
Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected products
-
- Version 0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| ChanGate | Property Management System | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Changate | Property Management System | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Contact the vendor to install the patch.
Weaknesses (1)
References (4)
- https://www.chtsecurity.com/news/4552fc54-18af-4c18-972d-394a68e44a39 third-party-advisory
- https://www.chtsecurity.com/news/8585c924-4a27-4337-bb44-684adc206432 third-party-advisory
- https://www.twcert.org.tw/en/cp-139-8141-9b045-2.html third-party-advisory
- https://www.twcert.org.tw/tw/cp-132-8140-ee91e-1.html third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.chtsecurity.com/news/4552fc54-18af-4c18-972d-394a68e44a39 | third-party-advisory | |
| https://www.chtsecurity.com/news/8585c924-4a27-4337-bb44-684adc206432 | third-party-advisory | |
| https://www.twcert.org.tw/en/cp-139-8141-9b045-2.html | third-party-advisory | |
| https://www.twcert.org.tw/tw/cp-132-8140-ee91e-1.html | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Oct 15, 2024
Updated Jan 9, 2025
Reserved Oct 15, 2024
Link CVE-2024-9972
CISA Vulnrichment
Updated Oct 15, 2024