A vulnerability, which was classified as critical, was found in SportsNET 4.0.1. This affects an unknown part of the file /app/ax/checkBlindFields/. The manipulation of the argument idChallenge/idEmpresa leads to sql injection.
This vulnerability is uniquely identified as CVE-2024-29731. It is possible to initiate the attack remotely. There is no exploit available.