CVE-2024-50706

Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:uniguest:tripleplay:*:*:*:*:*:*:*:*
cpe:2.3:a:uniguest:tripleplay:24.2:*:*:*:*:*:*:*

History

28 May 2025, 17:26

Type Values Removed Values Added
References () https://uniguest.com/cve-bulletins/ - () https://uniguest.com/cve-bulletins/ - Vendor Advisory
References () https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50706-Vulnerability-Summary.pdf - () https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50706-Vulnerability-Summary.pdf - Broken Link
CPE cpe:2.3:a:uniguest:tripleplay:*:*:*:*:*:*:*:*
cpe:2.3:a:uniguest:tripleplay:24.2:*:*:*:*:*:*:*
First Time Uniguest tripleplay
Uniguest

17 Apr 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de inyección SQL no autenticada en Uniguest Tripleplay anterior a 24.2.1 permite a atacantes remotos ejecutar consultas SQL arbitrarias en la base de datos del backend.
Summary (en) Unauthenticated SQL injection vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary SQL queries on the backend database. (en) Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.

04 Mar 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-89

04 Mar 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-04 15:15

Updated : 2025-05-28 17:26


NVD link : CVE-2024-50706

Mitre link : CVE-2024-50706

CVE.ORG link : CVE-2024-50706


JSON object : View

Products Affected

uniguest

  • tripleplay
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')