Логотип exploitDog
bind:CVE-2019-14937
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-14937

Количество 2

Количество 2

nvd логотип

CVE-2019-14937

больше 6 лет назад

REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4776-923q-4439

больше 3 лет назад

REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-14937

REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
github логотип
GHSA-4776-923q-4439

REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to compromise all data.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу