Vulnerability Details CVE-2024-7731
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-7731
-
cpe:2.3:a:secom:dr.id_access_control:-
-
cpe:2.3:a:secom:dr.id_access_control:3.3.2