Security Advisory

CVE-2024-9982

9.8
CRITICAL

Vulnerability Description

AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.
Published Date October 15, 2024
Official Source NIST NVD Advisory