CVE-2024-54820
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
XOne Web Monitor v02.10.2024.530 framework 1.0.4.9 was discovered to contain a SQL injection vulnerability in the login page. This vulnerability allows attackers to extract all usernames and passwords via a crafted input.
Published 2025-02-24. Last modified 2026-06-17.