CVE-2024-9982: Esi Technology Aim Line Marketing Platform

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers can inject arbitrary FetchXml commands to read, modify, and delete database content.

Affected products

  • Esi Technology Aim Line Marketing Platform: from 3.3, up to and including 5.8.4

Published 2024-10-15. Last modified 2026-06-17.