CVE-2024-51962 - CERT CVE
ID CVE-2024-51962
Sažetak A SQL injection vulnerability in ArcGIS Server allows an EDIT operation to modify Column properties allowing for the execution of a SQL Injection by a remote authenticated user with elevated (non admin) privileges.  There is a high impact to integrity and confidentiality and no impact to availability.
Reference
CVSS
Base: 8.7
Impact: 5.8
Exploitability:2.3
Pristup
VektorSloženostAutentikacija
NETWORK LOW HIGH
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH NONE
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Zadnje važnije ažuriranje 06-03-2025 - 14:23
Objavljeno 03-03-2025 - 20:15