Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r5f3-m4c7-2994

Опубликовано: 29 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.5
CVSS3: 8.8

Описание

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands.

We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands.

We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

EPSS

Процентиль: 26%
0.00093
Низкий

7.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later

EPSS

Процентиль: 26%
0.00093
Низкий

7.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-89