Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52mg-x4rg-p64j

Опубликовано: 30 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

EPSS

Процентиль: 41%
0.00193
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

EPSS

Процентиль: 41%
0.00193
Низкий

Дефекты

CWE-89