Описание
A vulnerability, which was classified as critical, has been found in IBAX go-ibax. Affected by this issue is some unknown functionality of the file /api/v2/open/rowsInfo. The manipulation of the argument table_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-212636.
Ссылки
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ibax:go-ibax:-:*:*:*:*:*:*:*
EPSS
Процентиль: 96%
0.25872
Средний
6.3 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-707
CWE-89
Связанные уязвимости
EPSS
Процентиль: 96%
0.25872
Средний
6.3 Medium
CVSS3
8.8 High
CVSS3
Дефекты
CWE-707
CWE-89