Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffh8-c8rh-cmp2

Опубликовано: 10 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

EPSS

Процентиль: 68%
0.00558
Низкий

10 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 10
nvd
больше 2 лет назад

Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12.

EPSS

Процентиль: 68%
0.00558
Низкий

10 Critical

CVSS3

Дефекты

CWE-89