Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3mmm-4792-65w2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

EPSS

Процентиль: 72%
0.0074
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

EPSS

Процентиль: 72%
0.0074
Низкий

Дефекты

CWE-89