VulnerabilityModified
CVE-2012-10006
A vulnerability classified as critical has been found in ale7714 sigeprosi.
CRITICAL 9.8EPSS 0.61%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability classified as critical has been found in ale7714 sigeprosi. This affects an unknown part. The manipulation leads to sql injection. The identifier of the patch is 5291886f6c992316407c376145d331169c55f25b. It is recommended to apply a patch to fix this issue. The identifier VDB-218493 was assigned to this vulnerability.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sigeprosi project/sigeprosi
- Source
- cna@vuldb.com
References
- https://github.com/ale7714/sigeprosi/commit/5291886f6c992316407c376145d331169c55f25bPatch, Third Party Advisory
- https://vuldb.com/?ctiid.218493Permissions Required, Third Party Advisory
- https://vuldb.com/?id.218493Third Party Advisory
- https://github.com/ale7714/sigeprosi/commit/5291886f6c992316407c376145d331169c55f25bPatch, Third Party Advisory
- https://vuldb.com/?ctiid.218493Permissions Required, Third Party Advisory
- https://vuldb.com/?id.218493Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.