Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-3059

Опубликовано: 31 окт. 2022
Источник: nvd
CVSS3: 8.6
CVSS3: 7.5
EPSS Низкий

Описание

The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:schoolbox:schoolbox:21.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.0006
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 7.5
github
больше 2 лет назад

The application was vulnerable to multiple instances of SQL injection (authenticated and unauthenticated) through a vulnerable parameter. Due to the stacked query support, complex SQL commands could be crafted and injected into the vulnerable parameter and using a sleep based inferential SQL injection it was possible to extract data from the database.

CVSS3: 9.8
redos
около 2 лет назад

Множественные уязвимости python-pillow

EPSS

Процентиль: 19%
0.0006
Низкий

8.6 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-89
CWE-89