Описание
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.
Ссылки
- Vendor Advisory
- Release NotesThird Party Advisory
- Vendor Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cliniccases:cliniccases:7.3.3:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00447
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.
EPSS
Процентиль: 63%
0.00447
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89