9.8
CVSSv3

CVE-2024-26264

Published: 15/02/2024 Updated: 15/02/2024
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote malicious users to inject SQL commands without authentication, enabling them to read, modify, and delete database records.