Junglewise Threat Intelligence

CVE-2024-11739: Case Informatics Case ERP SQL injection

CVE-2024-11739 · Severity: critical · CVSS 9.8 · Published 2025-06-27

Executive brief

Case Informatics Case ERP, a software suite used for managing business processes and resources, contains a critical security flaw. An attacker can use this vulnerability to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive corporate data or the complete disruption of business operations. This issue can be exploited remotely without requiring any user interaction or login credentials.

Technical details

A SQL injection vulnerability exists in Case Informatics Case ERP due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries. Successful exploitation could lead to full unauthorized access to the database, including the ability to read, modify, or delete sensitive data, and potentially achieve administrative control over the application. The vulnerability is addressed in version V2.0.1.

Affected products

  • Case Informatics Case ERP before V2.0.1

Timeline

  • 2025-06-27: advisory: Initial NVD publication date
  • 2026-06-02: other: Last modified date in NVD record

References