CVE-2024-54761
MEDIUMBigantsoft Bigant Office Messenger 5 - SQL Injection
Title source: ruleDescription
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
Exploits (2)
exploitdb
WORKING POC
by Nicat Abbasov · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52412
Scores
CVSS v3
6.3
EPSS
0.0033
EPSS Percentile
55.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Details
CWE
CWE-89
Status
published
Products (1)
bigantsoft/bigant_office_messenger_5
5.6.0.6
Published
Jan 09, 2025
Tracked Since
Feb 18, 2026