RULE(RULE ID:338233)

Rule General Information
Release Date: 2024-07-09
Rule Name: Flyrise FE Enterprise Operations Management Platform efficientCodewidget3 SQL Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: The Flyrise FE Enterprise Operations Management Platform is an integrated Enterprise Resource Planning (ERP) system designed to enhance operational efficiency and managerial decision-making through its integrated business process management and data analysis capabilities. Its efficientCodewidget39 interface has a SQL injection vulnerability, which attackers can exploit to execute malicious SQL commands, thereby gaining access to, tampering with, or deleting sensitive information in the database, posing a serious threat to data security and system integrity.
Impact: An attacker can inject arbitrary sql commands to view or change the database of the target by exploiting the vulnerability successfully.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.