HIGH🇵🇱 Wersja polska

CVE-2018-12977

CVSS 8.8v3.0pub. 2018-07-09upd. 2024-11-21

A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downloading Electronic Documents" section.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Softexpert Excellence Suite

    APP
    Softexpert
    2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2023-30330CRITICAL9.8PL ✓same product

Local File Inclusion w SoftExpert Excellence Suite prowadzący do RCE

CVE-2023-33515MEDIUM5.4same product

SoftExpert Excellence Suite 2.1.9 is vulnerable to Cross Site Scripting (XSS) via query screens.