Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: perl538Packages.ProtocolWebSocket

Found 2 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2024-7202
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
Simopro Technology WinMatrix3 Web package - SQL Injection

The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

Affected products

Web
  • =<1.2.35.3
winmatrix3
  • =<1.2.35.3

Matching in nixpkgs

Package maintainers

Untriaged
Permalink CVE-2024-7201
9.8 CRITICAL
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): LOW
  • Privileges required (PR): NONE
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
Simopro Technology WinMatrix3 Web package - SQL Injection

The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

Affected products

Web
  • =<1.2.33.3
winmatrix3
  • =<1.2.33.3

Matching in nixpkgs

Package maintainers