RULE(RULE ID:338221)

Rule General Information
Release Date: 2024-07-02
Rule Name: Pantosoft Credit System GetCalendarContentById SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The credit system GetCalendarContentById developed by Pantosoft has a SQL injection vulnerability. Unauthenticated remote attackers can exploit SQL injection vulnerabilities to inject malicious SQL statements, thereby obtaining sensitive information or controlling the database.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.