PT-2026-57753 · Latepoint+1 · Latepoint
CVE-2026-57714
·
Published
2026-07-08
·
Updated
2026-07-13
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
LatePoint versions prior to 5.6.4
Description
An issue exists due to insufficient escaping of user-supplied parameters and a lack of sufficient preparation of SQL queries. This allows unauthenticated attackers to perform Blind SQL Injection, a technique used to extract sensitive information from a database by asking the server true or false questions. The flaw enables the appending of additional SQL queries into existing ones.
Recommendations
Update to a version newer than 5.6.3.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Latepoint