Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mch-6pwv-9qcv

Опубликовано: 07 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

EPSS

Процентиль: 34%
0.00137
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

EPSS

Процентиль: 34%
0.00137
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89