Cyber Posture

CVE-2024-50706

Critical

Published: 04 March 2025

Published
04 March 2025
Modified
28 May 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0050 65.8th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2024-50706 is an unauthenticated SQL injection vulnerability (CWE-89) affecting Uniguest Tripleplay version 23.1 and later. It enables remote attackers to execute arbitrary SQL queries on the backend database. The vulnerability has a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity due to its network accessibility, low complexity, lack of privileges or user interaction requirements, and high impacts on confidentiality, integrity, and availability.

Remote attackers without authentication can exploit this vulnerability over the network by injecting malicious SQL payloads into affected endpoints. Successful exploitation allows arbitrary SQL query execution, potentially leading to full database compromise, including data extraction, modification, or deletion, as reflected in the high impact metrics.

Uniguest has published mitigation guidance in its CVE bulletins at https://uniguest.com/cve-bulletins/ and a dedicated vulnerability summary PDF at https://uniguest.com/wp-content/uploads/2025/02/CVE-2024-50706-Vulnerability-Summary.pdf. Security practitioners should consult these advisories for patching instructions and workarounds.

Details

CWE(s)
CWE-89

Affected Products

uniguest
tripleplay
24.2 · 23.1 — 24.1.2

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Unauthenticated remote SQL injection in a public-facing application directly enables exploitation of public-facing applications.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References