CVE-2024-36840: Boelter Blue System Management

Critical severity, CVSS 9.1. EPSS: 2.2% chance of exploitation in the next 30 days.

SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.

Affected products

  • Boelter Blue System Management: up to and including 1.3

Published 2024-06-12. Last modified 2026-06-17.