Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54qp-7v9c-7xqf

Опубликовано: 09 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disclose the contents of the database and obtain administrator's token to modify the content of pages.  This issue affects MegaBIP software versions through 5.13.

SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disclose the contents of the database and obtain administrator's token to modify the content of pages.  This issue affects MegaBIP software versions through 5.13.

EPSS

Процентиль: 18%
0.00057
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
больше 1 года назад

SQL Injection vulnerability in parameter "w" in file "druk.php" in MegaBIP software allows unauthorized attacker to disclose the contents of the database and obtain administrator's token to modify the content of pages.  This issue affects MegaBIP software versions through 5.13.

EPSS

Процентиль: 18%
0.00057
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-89