ZeroHour

CVE-2020-15924

PoC
CVSS 3.1
7.5 high
EPSS
2%p78
Published
()
Modified
Description

There is a SQL Injection in Mida eFramework through 2.9.0 that leads to Information Disclosure. No authentication is required. The injection point resides in one of the authentication parameters.

Vendors
midasolutions
Products
eframework
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.