ZeroHour

CVE-2022-44785

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p56
Published
()
Modified
Description

An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.

Vendors
maggioli
Products
appalti \& contratti
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.