Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14807

Опубликовано: 27 янв. 2020
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data. This issue affects: SUSE Studio onsite susestudio-ui-server version 1.3.17-56.6.3 and prior versions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:suse:studio_onsite:1.3:*:*:*:*:*:*:*
cpe:2.3:a:suse:susestudio-ui-server:*:*:*:*:*:*:*:*
Версия до 1.3.17-56.6.3 (включая)

EPSS

Процентиль: 38%
0.00171
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89

Связанные уязвимости

github
больше 3 лет назад

An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data. This issue affects: SUSE Studio onsite susestudio-ui-server version 1.3.17-56.6.3 and prior versions.

EPSS

Процентиль: 38%
0.00171
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-89
CWE-89