Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7q82-fxvh-gf2x

Опубликовано: 15 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

EPSS

Процентиль: 78%
0.01166
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.1
nvd
около 1 года назад

Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

EPSS

Процентиль: 78%
0.01166
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-89