ZeroHour

CVE-2022-32456

CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.

Vendors
digiwin
Products
business process management
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.