CVE-2024-11504 Information

Description

Input from multiple fields in Streamsoft Prestiz is not sanitized properly leading to an SQL injection vulnerability which might be exploited by an authenticated remote attacker.  This issue was fixed in 18.1.376.37 version of the software.

Reference

https://cert.pl/en/posts/2025/03/CVE-2024-7407/ https://www.streamsoft.pl/streamsoft-prestiz/

Share on: