CVE-2024-50706: Uniguest Tripleplay

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.

Affected products

  • Uniguest Tripleplay: from 23.1, before 24.1.2 (fixed in 24.1.2); version 24.2 only

Published 2025-03-04. Last modified 2026-06-17.