Dismissed
Permalink
CVE-2019-25457
8.2 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
2 packages
- tests.home-assistant-component-tests.firmata
- home-assistant-component-tests.firmata
- @LeSuisse dismissed
Web Ofisi Firma v13 SQL Injection via oz Parameter
Web Ofisi Firma v13 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'oz' array parameter. Attackers can send GET requests to category pages with malicious 'oz[]' values using time-based blind SQL injection payloads to extract sensitive database information.
References
-
ExploitDB-47145 exploit
-
Official Product Homepage product
-
VulnCheck Advisory: Web Ofisi Firma v13 SQL Injection via oz Parameter third-party-advisory
Affected products
Firma
- ==v13
Ignored packages (2)
pkgs.home-assistant-component-tests.firmata
None
pkgs.tests.home-assistant-component-tests.firmata
Open source home automation that puts local control and privacy first