Описание
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.
Ссылки
- Broken Link
- ExploitThird Party Advisory
- Product
- Broken Link
- ExploitThird Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sysaid:sysaid:20.4.74:b10:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00583
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
около 4 лет назад
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.
EPSS
Процентиль: 68%
0.00583
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89