Lucene search

K
cveVulDBCVE-2024-4653
HistoryMay 08, 2024 - 3:15 p.m.

CVE-2024-4653

2024-05-0815:15:11
CWE-89
VulDB
web.nvd.nist.gov
29
bluenet technology clinical browsing system
sql injection
remote attack
vulnerability
exploit disclosure
nvd

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

7.3

Confidence

Low

EPSS

0

Percentile

15.5%

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the file /xds/outIndex.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263498 is the identifier assigned to this vulnerability.

Affected configurations

Vulners
Node
bluenet_technologyclinical_browsing_systemMatch1.2.1
VendorProductVersionCPE
bluenet_technologyclinical_browsing_system1.2.1cpe:2.3:a:bluenet_technology:clinical_browsing_system:1.2.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "BlueNet Technology",
    "product": "Clinical Browsing System",
    "versions": [
      {
        "version": "1.2.1",
        "status": "affected"
      }
    ]
  }
]

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

7.3

Confidence

Low

EPSS

0

Percentile

15.5%

Related for CVE-2024-4653