Back to search
CVE-2024-50584
Published: Dec 12, 2024
Modified: Nov 3, 2025
PUBLISHED
Description
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.
| Vendor | Product | Versions |
|---|---|---|
Image Access GmbH | Scan2Net | affected 0 - < 7.42 |
Weaknesses (CWE)
References
https://r.sec-consult.com/imageaccess
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now