Vulnerabilities (CVE)

Filtered by vendor Softwareupdate Project Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-15887 1 Softwareupdate Project 1 Softwareupdate 2024-11-21 6.5 MEDIUM 8.8 HIGH
A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport allows attackers to execute arbitrary SQL commands via the last URL parameter of the /module/softwareupdate/get_tab_data/ endpoint.