Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6m83-456q-vvpj

Опубликовано: 25 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

EPSS

Процентиль: 25%
0.00088
Низкий

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.

EPSS

Процентиль: 25%
0.00088
Низкий

7.5 High

CVSS3

Дефекты

CWE-89