Описание
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.6.0.1 (исключая)
cpe:2.3:a:orangehrm:orangehrm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 79%
0.01236
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.1
debian
около 5 лет назад
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remot ...
github
больше 3 лет назад
SQL injection in the Buzz module of OrangeHRM through 4.6 allows remote authenticated attackers to execute arbitrary SQL commands via the orangehrmBuzzPlugin/lib/dao/BuzzDao.php loadMorePostsForm[profileUserId] parameter to the buzz/loadMoreProfile endpoint.
EPSS
Процентиль: 79%
0.01236
Низкий
8.1 High
CVSS3
5.5 Medium
CVSS2
Дефекты
CWE-89