CVE-2024-7732: Secom Dr.id Attendance System
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
Affected products
- Secom Dr.id Attendance System: before 3.5.0.0.0.5 (fixed in 3.5.0.0.0.5)
Published 2024-08-14. Last modified 2026-06-17.