Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vv22-vwq7-hqwj

Опубликовано: 08 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6

Описание

The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for authenticated administrative users to trigger SQL Injection.

This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06.

The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for authenticated administrative users to trigger SQL Injection.

This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06.

EPSS

Процентиль: 65%
0.00487
Низкий

6 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.6
nvd
10 месяцев назад

The DB chooser functionality in Jalios JPlatform 10 SP6 before 10.0.6 improperly neutralizes special elements used in an SQL command allows for unauthenticated users to trigger SQL Injection. This issue affects JPlatform before 10.0.6 and a PatchPlugin release 10.0.6 was issued 2023-02-06.

EPSS

Процентиль: 65%
0.00487
Низкий

6 Medium

CVSS3

Дефекты

CWE-89