ZeroHour

CVE-2020-22669

PoC ×2
CVSS 3.1
9.8 critical
EPSS
1%p69
Published
()
Modified
Description

Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.

Vendors
owaspdebian
Products
owasp modsecurity core rule set, debian linux
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.