CVE-2024-9972: ChanGate Property Management System - SQL Injection

9.8 CVSS

Description

Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Classification

CVE ID: CVE-2024-9972

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

Affected Products

Vendor: ChanGate

Product: Property Management System

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.82% (scored less or equal to compared to others)

EPSS Date: 2025-02-07 (when was this score calculated)

References

https://www.twcert.org.tw/tw/cp-132-8140-ee91e-1.html
https://www.twcert.org.tw/en/cp-139-8141-9b045-2.html
https://www.chtsecurity.com/news/8585c924-4a27-4337-bb44-684adc206432
https://www.chtsecurity.com/news/4552fc54-18af-4c18-972d-394a68e44a39

Timeline