CVE-2024-9972
CRITICALProperty Management System from ChanGate - SQL Injection
Title source: llmDescription
Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
References (4)
Core 4
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-8140-ee91e-1.html
Various Sources third-party-advisory
https://www.twcert.org.tw/en/cp-139-8141-9b045-2.html
Various Sources third-party-advisory
https://www.chtsecurity.com/news/8585c924-4a27-4337-bb44-684adc206432
Various Sources third-party-advisory
https://www.chtsecurity.com/news/4552fc54-18af-4c18-972d-394a68e44a39
Scores
CVSS v3
9.8
EPSS
0.0066
EPSS Percentile
47.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
ChanGate/Property Management System
Published
Oct 15, 2024
Tracked Since
Feb 18, 2026