CVE-2024-38882
Critical · CVSS 9.8Horizon Business Services Caterease — SQL Injection leading to OS Command Injection (CWE-78)
- CVSS
- 9.8
- nvd
- EPSS
- 0.95%
- 57th pct
- KEV
- No
- Class
- other
- CWE-78
Description
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.
Search profile — drives PoC discovery
Symbols xp_cmdshellSQL Injectioncommand injectionOS command executionCatereaseremote attackerspecial elements neutralization
Keywords CVE-2024-38882Caterease SQL InjectionCaterease command injectionCaterease 16.0.1.1663Caterease 24.0.1.2405Horizon Business Services exploitCaterease RCECaterease PoCCaterease SQLi OS command
Versions: 16.0.1.1663 through 24.0.1.2405
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z