CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2024-38882

Critical · CVSS 9.8

Horizon Business Services Caterease — SQL Injection leading to OS Command Injection (CWE-78)

CVSS
9.8
nvd
EPSS
0.95%
57th pct
KEV
No
Class
other
CWE-78

Description

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.

Search profile — drives PoC discovery

Symbols xp_cmdshellSQL Injectioncommand injectionOS command executionCatereaseremote attackerspecial elements neutralization
Keywords CVE-2024-38882Caterease SQL InjectionCaterease command injectionCaterease 16.0.1.1663Caterease 24.0.1.2405Horizon Business Services exploitCaterease RCECaterease PoCCaterease SQLi OS command
Versions: 16.0.1.1663 through 24.0.1.2405

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T00:30:39.000Z