CVE-2024-51165: Ketr Jepaas

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

Affected products

  • Ketr Jepaas: version 7.2.8 only

Published 2024-12-10. Last modified 2026-06-17.