CVE-2024-55971 Details
Description
SQL Injection vulnerability in the default configuration of the Logitime WebClock application <= 5.43.0 allows an unauthenticated user to run arbitrary code on the backend database server.
A SQL injection vulnerability has been identified in the Logitime WebClock application, in versions through 5.43.0. This vulnerability allows an unauthenticated user to execute arbitrary code on the backend database server. The issue arises from the application using a default database user with full permissions, which can be exploited by sending a specially crafted request to the web application.
Users are advised to update to version 5.44.0 or later and to configure the application to use a dedicated database user with limited permissions, as outlined in the documentation for the new version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 23, 2025CISA-ADP
Assessed Jan 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://en.logitime.com/time-attendance/ | [email protected] | Vendor |
| https://nl.logitime.com/ | [email protected] | Vendor |
| https://nl.logitime.com/download/webclock-v5-43-0-13-12-2024/ | [email protected] | Release NotesVendor |
| https://tulling.dev/disclosures/cve-2024-55971/ | [email protected] | AdvisoryRemedyTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Logitime WebClock | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | New CVE Received | [email protected] |
Volerion