CVE-2024-26264: Ebmtech Risweb
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database records.
Affected products
- Ebmtech Risweb: from 1.0, before 3.0 (fixed in 3.0)
Published 2024-02-15. Last modified 2026-06-17.