CVE-2024-55971 Information
Jan 25, 2025
cve
Description
SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauthenticated user to run arbitrary code on the backend database server.
Reference
https://en.logitime.com/time-attendance/ https://nl.logitime.com/ https://nl.logitime.com/download/webclock-v5-43-0-13-12-2024/ https://tulling.dev/disclosures/cve-2024-55971/
Share on: