Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wj4-5pg3-mprq

Опубликовано: 25 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/include/ajax.php' endpoint.

A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/include/ajax.php' endpoint.

EPSS

Процентиль: 10%
0.00034
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
14 дней назад

A SQL Injection vulnerability has been found in Support Board v3.7.7. This vulnerability allows an attacker to retrieve, create, update and delete database via 'calls[0][message_ids][]' parameter in '/supportboard/include/ajax.php' endpoint.

EPSS

Процентиль: 10%
0.00034
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89