ZeroHour

CVE-2023-36652

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p47
Published
()
Modified
Description

A SQL Injection in the users searching REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to read database data via SQL commands injected in the search parameter.

Vendors
prolion
Products
cryptospike
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.