CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2020-12-23T17:19:58
Updated: 2024-08-04T12:32:14.598Z
Reserved: 2020-06-09T00:00:00
Link: CVE-2020-13968

No data.

Status : Modified
Published: 2020-12-23T18:15:12.650
Modified: 2024-11-21T05:02:15.693
Link: CVE-2020-13968

No data.