ZeroHour

CVE-2023-40787

CVSS 3.1
9.8 critical
EPSS
18%p97
Published
()
Modified
Description

In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.

Vendors
bladex
Products
springblade
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.