Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7pjj-5xf2-pmpg

Опубликовано: 06 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands.

We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands.

We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

EPSS

Процентиль: 25%
0.00081
Низкий

8.7 High

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
13 дней назад

An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later

CVSS3: 8.8
fstec
12 дней назад

Уязвимость приложения для синхронизации файлов Qsync Central, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 25%
0.00081
Низкий

8.7 High

CVSS4

Дефекты

CWE-89