Zurück zur CVE-Übersicht
CVE-2020-28860
HIGH(8.8)CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Risk Signal Score23/100 — NIEDRIG
- CVSS 8.8 — Hoch
EPSS-Score
2%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.8
Technische Schwere
Beschreibung
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
Referenzen
- http://packetstormsecurity.com/files/160459/OpenAsset-Digital-Asset-Management-S...
- http://seclists.org/fulldisclosure/2020/Dec/21
- https://www.themissinglink.com.au/security-advisories-cve-2020-28860
- http://openasset.com
- http://packetstormsecurity.com/files/160459/OpenAsset-Digital-Asset-Management-S...
- http://seclists.org/fulldisclosure/2020/Dec/21
- https://www.themissinglink.com.au/security-advisories-cve-2020-28860