CVE-2024-13151
BaseFortify
Publication date: 2025-09-18
Last updated on: 2025-10-03
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| esbi_information_and_telecommunication_industry_and_trade_limited_company | auto_service_software | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an SQL Injection in Logo Software Retail Sales Management that allows an attacker to bypass authorization by manipulating a user-controlled SQL primary key. It is classified as CWE-89, which involves improper neutralization of special elements used in an SQL command, specifically a Blind SQL Injection (CAPEC-7).
How can this vulnerability impact me? :
The vulnerability can have severe impacts including unauthorized access to sensitive data, complete compromise of confidentiality, integrity, and availability of the affected system, as indicated by the highest CVSS score of 10.0 with network attack vector, no privileges required, and no user interaction needed.