Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9x3-f4wq-53xg

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL injection vulnerability in the brilliant_gallery_checklist_save function in the bgchecklist/save script in Brilliant Gallery 5.x and 6.x, a module for Drupal, allows remote authenticated users with "access brilliant_gallery" permissions to execute arbitrary SQL commands via the (1) nid, (2) qid, (3) state, and possibly (4) user parameters.

SQL injection vulnerability in the brilliant_gallery_checklist_save function in the bgchecklist/save script in Brilliant Gallery 5.x and 6.x, a module for Drupal, allows remote authenticated users with "access brilliant_gallery" permissions to execute arbitrary SQL commands via the (1) nid, (2) qid, (3) state, and possibly (4) user parameters.

EPSS

Процентиль: 64%
0.00461
Низкий

Дефекты

CWE-89

Связанные уязвимости

nvd
больше 17 лет назад

SQL injection vulnerability in the brilliant_gallery_checklist_save function in the bgchecklist/save script in Brilliant Gallery 5.x and 6.x, a module for Drupal, allows remote authenticated users with "access brilliant_gallery" permissions to execute arbitrary SQL commands via the (1) nid, (2) qid, (3) state, and possibly (4) user parameters.

EPSS

Процентиль: 64%
0.00461
Низкий

Дефекты

CWE-89