Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4m7-j2g3-gvpf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

EPSS

Процентиль: 57%
0.00351
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

rConfig 3.9.5 is vulnerable to SQL injection. A remote authenticated attacker could send crafted SQL statements to the devices.crud.php script using the custom_Location parameter, which could allow the attacker to view, add, modify, or delete information in the back-end database.

EPSS

Процентиль: 57%
0.00351
Низкий