Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xhxm-v6fm-53p3

Опубликовано: 15 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.

In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.

EPSS

Процентиль: 76%
0.00946
Низкий

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.

EPSS

Процентиль: 76%
0.00946
Низкий

Дефекты

CWE-89