Dismissed
Permalink
CVE-2020-37154
7.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
6 packages
- haskellPackages.selections
- haskellPackages.cardano-coin-selection
- kakounePlugins.kakoune-vertical-selection
- python313Packages.colcon-package-selection
- python314Packages.colcon-package-selection
- vscode-extensions.albymor.increment-selection
- @LeSuisse dismissed
eLection 2.0 - 'id' SQL Injection
eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can leverage SQLMap to exploit the vulnerability, potentially gaining remote code execution by uploading backdoor files to the web application directory.
References
-
ExploitDB-48122 exploit
-
eLection Project Vendor Homepage product
-
-
VulnCheck Advisory: eLection 2.0 - 'id' SQL Injection third-party-advisory
Affected products
eLection
- ==2.0
Ignored packages (6)
pkgs.haskellPackages.selections
Combinators for operating with selections over an underlying functor
pkgs.haskellPackages.cardano-coin-selection
Algorithms for coin selection and fee balancing
-
nixos-unstable 2023-04-20
- nixpkgs-unstable 2023-04-20
- nixos-unstable-small 2023-04-20
pkgs.python313Packages.colcon-package-selection
Extension for colcon to select the packages to process
pkgs.python314Packages.colcon-package-selection
Extension for colcon to select the packages to process
pkgs.vscode-extensions.albymor.increment-selection
Increment, decrement or reverse selection with multiple cursors