Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ccjc-vc4q-6gm3

Опубликовано: 23 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

EPSS

Процентиль: 79%
0.0125
Низкий

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость компонента group_list программного средства мониторинга состояния и функций маршрутизаторов Advantech R-SeeNet, позволяющая нарушителю выполнять произвольные SQL-запросы

EPSS

Процентиль: 79%
0.0125
Низкий

8.8 High

CVSS3

Дефекты

CWE-89