Vulnerability Details CVE-2024-1301
SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.106
EPSS Ranking 92.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-1301
-
cpe:2.3:a:badgermeter:monitool:-
-
cpe:2.3:a:badgermeter:monitool:4.6.3