CVE-2024-1301 is a high-severity SQL injection vulnerability affecting Badger Meter Monitool versions 4.6.3 and earlier. A remote attacker can exploit this by sending a specially crafted SQL query through the j_username parameter, allowing them to retrieve sensitive information from the database. With a CVSS score of 7.5 (HIGH) and an EPSS score indicating higher exploitability than 96.5% of CVEs, this vulnerability presents a significant risk. While there are no known public exploits or active exploitation reported, the vulnerability has garnered considerable community discussion, suggesting potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.7CPE matchmatch criteria | cpe:2.3:a:badgermeter:monitool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.