Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authenticated user via an API call.
https://www.bentley.com/advisories/be-2024-0002/
Source: Mitre, NVD
Published: 2025-01-31
Updated: 2025-01-31
Base Score: 4.5
Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:P/A:N
Severity: Medium
Base Score: 6.4
Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N