ZeroHour

CVE-2020-28860

PoC ×2
CVSS 3.1
8.8 high
EPSS
2%p81
Published
()
Modified
Description

OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.

Vendors
openasset
Products
digital asset management
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.