Описание
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application component. Crafted input can be executed as part of backend database queries. The issue is exploitable without authentication, significantly elevating the risk.
Ссылки
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 8.14.9 (исключая)
cpe:2.3:a:explorance:blue:*:*:*:*:*:*:*:*
EPSS
Процентиль: 26%
0.00092
Низкий
8.6 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 8.6
github
10 дней назад
Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user-supplied input in a web application component. Crafted input can be executed as part of backend database queries. The issue is exploitable without authentication, significantly elevating the risk.
EPSS
Процентиль: 26%
0.00092
Низкий
8.6 High
CVSS3
Дефекты
CWE-89