NVD disclosure day

Published threat advisories for September 16, 2024

CVE advisoryCRITICAL

CVE-2024-7098

SFS Winsure XML Injection Vulnerability Advisory.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An XML injection flaw in SFS Consulting ww.Winsure allows unauthorized data access or system disruption. This impacts organizations by potentially exposing sensitive information or hindering operations. The business risk involves unauthorized control or data compromise.

CVE advisoryCRITICAL

CVE-2024-6401

InsureE GL SQL Injection Vulnerability Advisory.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in InsureE GL software enables unauthorized data manipulation. This SQL injection flaw allows attackers to insert malicious commands, potentially compromising sensitive data and impacting financial reporting and system integrity. The risk to affected organizations is significant.