CVE-2024-11504: Streamsoft Prestiż

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Input from multiple fields in Streamsoft Prestiż is not sanitized properly, leading to an SQL injection vulnerability, which might be exploited by an authenticated remote attacker.  This issue was fixed in 18.1.376.37 version of the software.

Affected products

  • Streamsoft Streamsoft Prestiż: before 18.1.376.37 (fixed in 18.1.376.37)

Published 2025-03-28. Last modified 2026-06-17.