Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-88g9-2h5w-9543

Опубликовано: 14 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

EPSS

Процентиль: 13%
0.00044
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-89

Связанные уязвимости

CVSS3: 4.3
nvd
около 2 лет назад

There is a SQL injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of SMS interface parameter, an authenticated attacker could use the vulnerability to execute SQL injection and cause information leak.

EPSS

Процентиль: 13%
0.00044
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-89