Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8vmv-4hfm-2fv8

Опубликовано: 08 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.

We have already fixed the vulnerability in the following versions: myQNAPcloud 1.0.52 ( 2023/11/24 ) and later QTS 4.5.4.2627 build 20231225 and later

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.

We have already fixed the vulnerability in the following versions: myQNAPcloud 1.0.52 ( 2023/11/24 ) and later QTS 4.5.4.2627 build 20231225 and later

EPSS

Процентиль: 90%
0.05105
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 4.7
nvd
почти 2 года назад

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: myQNAPcloud 1.0.52 ( 2023/11/24 ) and later QTS 4.5.4.2627 build 20231225 and later

CVSS3: 4.7
fstec
почти 2 года назад

Уязвимость операционных систем QTS, QuTS Hero, QuTScloud и myQNAPcloud, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05105
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-89