Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rrv3-gjv6-v522

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure.

In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure.

EPSS

Процентиль: 67%
0.00533
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
больше 9 лет назад

In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure.

EPSS

Процентиль: 67%
0.00533
Низкий

7.5 High

CVSS3

Дефекты

CWE-200
CWE-89