Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95qh-rxf5-w7vp

Опубликовано: 04 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.

Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.

EPSS

Процентиль: 14%
0.00045
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.9
nvd
больше 2 лет назад

Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.

EPSS

Процентиль: 14%
0.00045
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-89