CVE-2024-9971

HIGH

FlowMaster BPM Plus - SQL Injection

Title source: llm
STIX 2.1

Description

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8138-d2bb7-1.html
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/en/cp-139-8139-4daab-2.html

Scores

CVSS v3 8.8
EPSS 0.0063
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
newtype/flowmaster_bpm_plus < 5.3.1
Published Oct 15, 2024
Tracked Since Feb 18, 2026