
lukaszstu/SmartAsset-SQLinj-CVE-2020-26525
Releases0
Stars1
Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter.
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 9.1 CRITICAL | 6.4 MEDIUM | ||
Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers. | |||