Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4q9-9x6g-wwh5

Опубликовано: 06 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.

A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.

EPSS

Процентиль: 36%
0.00152
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-917

Связанные уязвимости

CVSS3: 6.3
nvd
больше 1 года назад

A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMapper.java of the component Data Schema Page. The manipulation leads to improper neutralization of special elements used in an expression language statement. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273697 was assigned to this vulnerability.

EPSS

Процентиль: 36%
0.00152
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-917