Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-2681
HistoryOct 03, 2023 - 1:15 p.m.

Sql injection

2023-10-0313:15:00
PRIOn knowledge base
www.prio-n.com
7
sql injection
jorani
version 1.0.0
leaves validation
arbitrary information
database

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.3%

An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, to send queries with malicious SQL code on the “/leaves/validate” path and the “id” parameter, managing to extract arbritary information from the database.

CPENameOperatorVersion
joranieq1.0.0

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.3%

Related for PRION:CVE-2023-2681