Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7w2g-wqp8-2c9j

Опубликовано: 11 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

EPSS

Процентиль: 83%
0.01906
Низкий

8.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.5
nvd
больше 1 года назад

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database.

EPSS

Процентиль: 83%
0.01906
Низкий

8.5 High

CVSS3

Дефекты

CWE-89