CVE-2024-52335

A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en syngo.plaza VB30E (todas las versiones &lt; VB30E_HF05). La aplicación afectada no desinfecta correctamente los datos de entrada antes de enviarlos al servidor SQL. Esto podría permitir que un atacante con acceso a la aplicación use esta vulnerabilidad para ejecutar comandos SQL maliciosos y comprometer toda la base de datos.

06 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-06 14:15

Updated : 2026-04-15 00:35


NVD link : CVE-2024-52335

Mitre link : CVE-2024-52335

CVE.ORG link : CVE-2024-52335


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')