An SQL Injection vulnerability has... CVE-2023-2681

- AV AC AU C I A
发布: 2023-10-03
修订: 2023-10-25

An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the "/leaves/validate" path and the “id” parameter, managing to extract arbritary information from the database.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息