Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3639-77vf-hx6g

Опубликовано: 17 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.6

Описание

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

EPSS

Процентиль: 14%
0.00046
Низкий

7.6 High

CVSS3

Дефекты

CWE-74
CWE-89

Связанные уязвимости

CVSS3: 7.6
nvd
больше 2 лет назад

An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.

EPSS

Процентиль: 14%
0.00046
Низкий

7.6 High

CVSS3

Дефекты

CWE-74
CWE-89