Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9vwh-vqcj-qvf3

Опубликовано: 23 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6

Описание

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.

EPSS

Процентиль: 13%
0.00044
Низкий

8.6 High

CVSS4

Дефекты

CWE-89

Связанные уязвимости

nvd
9 месяцев назад

While editing pages managed by MegaBIP a user with high privileges is prompted to give a reasoning for performing this action. Input provided by the the user is not sanitized, leading to SQL Injection vulnerability.  Version 5.20 of MegaBIP fixes this issue.

EPSS

Процентиль: 13%
0.00044
Низкий

8.6 High

CVSS4

Дефекты

CWE-89