ZeroHour

CVE-2020-21176

PoC
CVSS 3.1
9.8 critical
EPSS
1%p73
Published
()
Modified
Description

SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.

Vendors
thinkjs
Products
thinkjs
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.