01642 06 11 11 Arrange Call

Critical SQL Injection Vulnerability in Badger Meter Monitool 4.6.3 and Earlier

CVE-2024-1301 · CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2024-1301

SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.

Learn more about our Cis Benchmark Audit For Server Software.