Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g6c-2vm9-2g8p

Опубликовано: 15 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

EPSS

Процентиль: 60%
0.00402
Низкий

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
11 месяцев назад

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

EPSS

Процентиль: 60%
0.00402
Низкий

8.8 High

CVSS3

Дефекты

CWE-89