Описание
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.
Комментарий
Per vendor advisory at: http://drupal.org/node/342246
"Versions Affected
Drupal core is not affected. If you do not use the Storm module, there is nothing you need to do.
Ссылки
- PatchVendor Advisory
- Vendor Advisory
- Patch
- PatchVendor Advisory
- Vendor Advisory
- Patch
Уязвимые конфигурации
Одновременно
Одно из
EPSS
6 Medium
CVSS2
Дефекты
Связанные уязвимости
SQL injection vulnerability in SpeedTech Organization and Resource Manager (Storm) 5.x before 5.x-1.14 and 6.x before 6.x-1.18, a module for Drupal, allows remote authenticated users with storm project access to execute arbitrary SQL commands via unspecified vectors.
EPSS
6 Medium
CVSS2