Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40842

Опубликовано: 13 окт. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthenticated APIs. A malicious URL visited by anyone with network access to the server could be used to blindly execute arbitrary SQL statements on the backend database. Version 7.12.0 and all versions prior to 7.11.2 are affected.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:proofpoint:insider_threat_management_server:*:*:*:*:*:*:*:*
Версия до 7.11.2 (исключая)
cpe:2.3:a:proofpoint:insider_threat_management_server:7.12.0:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00385
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

github
больше 3 лет назад

Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input validation on the database name parameter required in certain unauthenticated APIs. A malicious URL visited by anyone with network access to the server could be used to blindly execute arbitrary SQL statements on the backend database. Version 7.12.0 and all versions prior to 7.11.2 are affected.

EPSS

Процентиль: 59%
0.00385
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-89