Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4893

Опубликовано: 15 мая 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.

EPSS

Процентиль: 69%
0.00591
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, and delete database records, as well as execute system commands.

EPSS

Процентиль: 69%
0.00591
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89