CVE-2024-4257 is a critical SQL injection vulnerability in BlueNet Technology Clinical Browsing System version 1.2.1, specifically affecting the /xds/deleteStudy.php file through manipulation of the documentUniqueId argument. This vulnerability has a CVSS score of 6.5 (Medium) and can be exploited remotely with low attack complexity, potentially leading to high confidentiality impact. While not currently on CISA's KEV catalog, public exploit details are available, and Nuclei templates exist for detection. Despite its high EPSS and FAUCET risk scores, there is no reported active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.1CPE matchmatch criteria | cpe:2.3:a:bluenettechnology:clinical_browsing_system:1.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.