Guillermo García Molina

4 exploits Active since Mar 2024
CVE-2024-1301 NOMISEC CRITICAL WRITEUP
Badgermeter Monitool < 4.7 - SQL Injection
SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.
CVSS 9.8
CVE-2024-1302 NOMISEC HIGH WRITEUP
Badgermeter Monitool < 4.7 - Information Disclosure
Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.
CVSS 7.3
CVE-2024-1303 NOMISEC MEDIUM WRITEUP
Badgermeter Monitool < 4.7 - Path Traversal
Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an authenticated attacker to retrieve any file from the device using the download-file functionality.
CVSS 6.5
CVE-2024-1304 NOMISEC MEDIUM WORKING POC
Badgermeter Monitool < 4.7 - XSS
Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially crafted javascript payload to an authenticated user and partially hijack their browser session.
CVSS 6.3