CVE-2024-50706: Uniguest Tripleplay
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.
Affected products
- Uniguest Tripleplay: from 23.1, before 24.1.2 (fixed in 24.1.2); version 24.2 only
Published 2025-03-04. Last modified 2026-06-17.