Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6cr5-vh9x-gh55

Опубликовано: 10 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.

Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.

EPSS

Процентиль: 54%
0.00316
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.

EPSS

Процентиль: 54%
0.00316
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89