VYPR
Critical severity9.8NVD Advisory· Published Feb 10, 2019· Updated Jun 17, 2026

CVE-2018-13792

CVE-2018-13792

Description

Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter.

Affected products

2
  • ABBYY/FlexiCapturellm-fuzzy2 versions
    < 12 Release 2+ 1 more
    • (no CPE)range: < 12 Release 2
    • cpe:2.3:a:abbyy:flexicapture:*:*:*:*:*:*:*:*range: >=12.0,<12.0.2.1194

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.