There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information.
References
Link | Resource |
---|---|
https://www.incibe-cert.es/en/early-warning/security-advisories/gesio-sql-injection-vulnerability | Third Party Advisory |
https://www.incibe-cert.es/en/early-warning/security-advisories/gesio-sql-injection-vulnerability | Third Party Advisory |
Configurations
History
21 Nov 2024, 05:39
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 10.0 |
References | () https://www.incibe-cert.es/en/early-warning/security-advisories/gesio-sql-injection-vulnerability - Third Party Advisory |
Information
Published : 2020-06-01 14:15
Updated : 2024-11-21 05:39
NVD link : CVE-2020-8967
Mitre link : CVE-2020-8967
CVE.ORG link : CVE-2020-8967
JSON object : View
Products Affected
gesio
- erp
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')