Lucene search

K
osvGoogleOSV:GHSA-4QGH-M9VP-48XP
HistoryMay 24, 2022 - 5:24 p.m.

MunkiReport Software Update module is vulnerable to SQL injection

2022-05-2417:24:15
Google
osv.dev
3
munkireport
software update
sql injection

AI Score

8.6

Confidence

Low

EPSS

0.001

Percentile

47.2%

A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport allows attackers to execute arbitrary SQL commands via the last URL parameter of the /module/softwareupdate/get_tab_data/ endpoint.

AI Score

8.6

Confidence

Low

EPSS

0.001

Percentile

47.2%

Related for OSV:GHSA-4QGH-M9VP-48XP