CVE-2024-51962

CVSS 3.1 Score 9.6 of 10 (high)

Attack Complexity low
Confidentiality high
Integrity high
Scope changed
Privileges Required low
Availability none

Details

Published Mar 3, 2025
Updated: Mar 6, 2025
CWE ID 89

Summary

CVE-2024-51962 is a SQL injection vulnerability affecting ArcGIS Server. This issue allows an authenticated user with elevated, non-admin privileges to execute SQL injection during an EDIT operation, impacting both integrity and confidentiality of the data without affecting availability. By manipulating Column properties, malicious users can introduce malicious SQL statements, leading to unintended data modifications or exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share