Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6fv-cg9x-p5jx

Опубликовано: 10 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.

EPSS

Процентиль: 39%
0.00177
Низкий

7.5 High

CVSS3

Дефекты

CWE-89