ZeroHour

CVE-2020-3936

CVSS 3.1
9.8 critical
EPSS
1%p68
Published
()
Modified
Description

UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

Vendors
unisoon
Products
ultralog express firmware
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.