ZeroHour

CVE-2018-12977

CVSS 3.0
8.8 high
EPSS
1%p72
Published
()
Modified
Description

A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downloading Electronic Documents" section.

Vendors
softexpert
Products
excellence suite
Weakness
CWE-89
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.