Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hmx5-gpvw-gpv4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information.

SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information.

EPSS

Процентиль: 47%
0.00238
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information.

EPSS

Процентиль: 47%
0.00238
Низкий

Дефекты

CWE-89