Описание
An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingPatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.6.1 (исключая)
cpe:2.3:a:rosariosis:rosariosis:*:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.06197
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
EPSS
Процентиль: 91%
0.06197
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-89