Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-crcx-wcr8-prj5

Опубликовано: 25 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the transaction_delete_group function. The vulnerability is due to improper sanitization of user input in the TrDeleteArr parameter, which is directly incorporated into an SQL query.

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the transaction_delete_group function. The vulnerability is due to improper sanitization of user input in the TrDeleteArr parameter, which is directly incorporated into an SQL query.

EPSS

Процентиль: 29%
0.00104
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

Money Manager EX WebApp (web-money-manager-ex) 1.2.2 is vulnerable to SQL Injection in the `transaction_delete_group` function. The vulnerability is due to improper sanitization of user input in the `TrDeleteArr` parameter, which is directly incorporated into an SQL query.

EPSS

Процентиль: 29%
0.00104
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89