ZeroHour

CVE-2018-20469

PoC ×2
CVSS 3.1
9.8 critical
EPSS
19%p97
Published
()
Modified
Description

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions.

Vendors
sahipro
Products
sahi pro
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.