Описание
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.
EPSS
6.3 Medium
CVSS3
Дефекты
Связанные уязвимости
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticat ...
A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.
Уязвимость компонента смены пароля программного обеспечения для совместной работы SOGo, позволяющая нарушителю выполнить произвольный код или получить несанкционированный доступ к защищаемой информации
EPSS
6.3 Medium
CVSS3