Логотип exploitDog
bind:CVE-2019-11600
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-11600

Количество 2

Количество 2

nvd логотип

CVE-2019-11600

больше 6 лет назад

A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

CVSS3: 8.1
EPSS: Высокий
github логотип

GHSA-c233-43hc-2x3j

больше 3 лет назад

A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

CVSS3: 8.1
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-11600

A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

CVSS3: 8.1
81%
Высокий
больше 6 лет назад
github логотип
GHSA-c233-43hc-2x3j

A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

CVSS3: 8.1
81%
Высокий
больше 3 лет назад

Уязвимостей на страницу