Описание
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
EPSS
Процентиль: 15%
0.00239
Низкий
7.1 High
CVSS3
Дефекты
CWE-89
Связанные уязвимости
CVSS3: 7.1
ubuntu
3 месяца назад
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
CVSS3: 7.1
debian
3 месяца назад
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext ...
CVSS3: 7.1
github
3 месяца назад
SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.
EPSS
Процентиль: 15%
0.00239
Низкий
7.1 High
CVSS3
Дефекты
CWE-89