CVE-2024-53007
Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authenticated user via an API call.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.4
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N/E:P/RL:T/RC:C
- EPSS probability
- 0.13%
- CWE
- CWE-648
- Published
- 2025-01-31
- Last modified
- 2026-03-13
Affected products
- Bentley ProjectWise Integration Server
Weakness type
Related vulnerabilities
- CVE-2026-63727 — Anchore Enterprise Privilege Escalation via User Management API
- CVE-2026-54424 — An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a...
- CVE-2026-11877 — Missing Authorization Vulnerability in OpenText Access Manager
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-41225 — iControl REST vulnerability
- CVE-2026-41386 — OpenClaw < 2026.3.22 - Privilege Escalation via Unbound Bootstrap Setup Codes
- CVE-2026-41329 — OpenClaw < 2026.3.31 - Sandbox Bypass via Heartbeat Context Inheritance and senderIsOwner Escalation
- CVE-2026-35669 — OpenClaw < 2026.3.25 - Privilege Escalation via Gateway Plugin HTTP Authentication Scope