Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26712

Опубликовано: 12 янв. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vanderbilt:redcap:10.0.20:*:*:*:lts:*:*:*
cpe:2.3:a:vanderbilt:redcap:10.3.4:*:*:*:-:*:*:*

EPSS

Процентиль: 71%
0.00697
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
больше 3 лет назад

REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability where an attacker can exploit and compromise all databases.

EPSS

Процентиль: 71%
0.00697
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-89