Vulnerability Details CVE-2024-7732
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2024-7732
-
cpe:2.3:a:secom:dr.id_attendance_system:-
-
cpe:2.3:a:secom:dr.id_attendance_system:3.3.0.3_20160517
-
cpe:2.3:a:secom:dr.id_attendance_system:3.4.0.0.3.11