VulnerabilityModified
CVE-2024-0857
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc.
CRITICAL 9.8EPSS 0.42%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection. This issue affects FlexWater Corporate Water Management: before 5.452.0.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.42% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- uni-yaz/flexwater corporate water management
- Source
- iletisim@usom.gov.tr
References
- https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-24-1011
- https://www.usom.gov.tr/bildirim/tr-24-1011Third Party Advisory
- https://www.usom.gov.tr/bildirim/tr-24-1011Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.