Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h29-88h5-g2w2

Опубликовано: 20 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

EPSS

Процентиль: 82%
0.01705
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

GRANDCOM DynWEB before 4.2 contains a SQL Injection vulnerability in the admin login interface. A remote unauthenticated attacker can exploit this vulnerability to obtain administrative access to the webpage, access the user database, modify web content and upload custom files. The backend login script does not verify and sanitize user-provided strings.

EPSS

Процентиль: 82%
0.01705
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89