Описание
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.
Ссылки
- ExploitThird Party Advisory
- ExploitTechnical DescriptionThird Party Advisory
- ExploitThird Party Advisory
- ExploitTechnical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:mv:idce:1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00328
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.
EPSS
Процентиль: 55%
0.00328
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-89