CVE-2024-13928
Last modified
CVE-2024-13928 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:C/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-13928?
How severe is CVE-2024-13928?
How do I fix CVE-2024-13928?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-13921The Order Export & Order Import for WooCommerce plugin for W…7.2
- CVE-2024-13922The Order Export & Order Import for WooCommerce plugin for W…6.5
- CVE-2024-13923The Order Export & Order Import for WooCommerce plugin for W…6.5
- CVE-2024-13924The Starter Templates by FancyWP plugin for WordPress is vul…9.1
- CVE-2024-13925The Klarna Checkout for WooCommerce WordPress plugin before …7.5
- CVE-2024-13926The WP-Syntax WordPress plugin through 1.2 does not properly…7.5
- CVE-2024-13929Servlet injection vulnerabilities in ASPECT allow remote cod…7.5
- CVE-2024-1393The Elementor Addon Elements plugin for WordPress is vulnera…5.4
- CVE-2024-13930An Unchecked Loop Condition in ASPECT provides an attacker t…5.9
- CVE-2024-13931Relative Path Traversal vulnerabilities in ASPECT allow acce…7.5
- CVE-2024-13933The FoodBakery | Delivery Restaurant Directory WordPress The…8.8
- CVE-2024-13939String::Compare::ConstantTime for Perl through 0.321 is vuln…7.5
Are you affected by CVE-2024-13928?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
