| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33650 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which allocated from heap buffers. | ||
| CVE-2021-33649 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater than or equal to the size of the input_shape, it will access data outside of bounds of input_shape which allocated from heap buffers. | ||
| CVE-2021-33648 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers. | ||
| CVE-2021-33647 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will access data outside of bounds of heap allocated buffers. | ||
| CVE-2022-2210 | Hig | 0.00 | 7.8 | 0.01 | Jun 27, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2021-40901 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails. | ||
| CVE-2021-40900 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails. | ||
| CVE-2022-2207 | Hig | 0.00 | 7.8 | 0.01 | Jun 27, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0722 | Hig | 0.42 | 7.5 | 0.01 | Jun 27, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0. | ||
| CVE-2021-40899 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories. | ||
| CVE-2021-40898 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files. | ||
| CVE-2021-40897 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls. | ||
| CVE-2021-40896 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails. | ||
| CVE-2021-40895 | Hig | 0.49 | 7.5 | 0.01 | Jun 27, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements. | ||
| CVE-2022-1977 | Hig | 0.47 | 7.2 | 0.01 | Jun 27, 2022 | The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks | ||
| CVE-2022-1903 | Hig | 0.53 | 8.1 | 0.09 | Jun 27, 2022 | The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their… | ||
| CVE-2022-1572 | Hig | 0.53 | 8.1 | 0.01 | Jun 27, 2022 | The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file | ||
| CVE-2022-33202 | Hig | 0.53 | 8.1 | 0.00 | Jun 27, 2022 | Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by… | ||
| CVE-2022-2206 | Hig | 0.00 | 7.8 | 0.01 | Jun 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-24893 | Hig | 0.49 | 7.5 | 0.01 | Jun 25, 2022 | ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can… | ||
| CVE-2021-40894 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called. | ||
| CVE-2022-33121 | Hig | 0.53 | 8.1 | 0.00 | Jun 24, 2022 | A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link. | ||
| CVE-2022-21231 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666) | ||
| CVE-2022-22390 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973. | ||
| CVE-2021-40893 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating crafted invalid emails. | ||
| CVE-2020-21046 | Hig | 0.51 | 7.8 | 0.00 | Jun 24, 2022 | A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as… | ||
| CVE-2022-2121 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition. | ||
| CVE-2022-2120 | Hig | 0.49 | 7.5 | 0.03 | Jun 24, 2022 | OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution. | ||
| CVE-2022-2119 | Hig | 0.49 | 7.5 | 0.03 | Jun 24, 2022 | OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution. | ||
| CVE-2022-28619 | Hig | 0.51 | 7.8 | 0.00 | Jun 24, 2022 | A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The vulnerability could allow local escalation of privilege. HPE has made the following software update to resolve the vulnerability in HPE Version Control… | ||
| CVE-2022-1746 | Hig | 0.49 | 7.6 | 0.00 | Jun 24, 2022 | The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive… | ||
| CVE-2022-1667 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script | ||
| CVE-2022-1524 | Hig | 0.48 | 7.4 | 0.00 | Jun 24, 2022 | LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials. | ||
| CVE-2013-1916 | Hig | 0.54 | 8.8 | 0.12 | Jun 24, 2022 | In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved. | ||
| CVE-2021-40892 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling crafted invalid rgb(a) strings. | ||
| CVE-2021-41638 | Hig | 0.49 | 7.5 | 0.02 | Jun 24, 2022 | The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username. | ||
| CVE-2021-41637 | Hig | 0.46 | 7.1 | 0.00 | Jun 24, 2022 | Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users. | ||
| CVE-2021-41635 | Hig | 0.57 | 8.8 | 0.02 | Jun 24, 2022 | When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system. | ||
| CVE-2022-32143 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker… | ||
| CVE-2022-32142 | Hig | 0.53 | 8.1 | 0.01 | Jun 24, 2022 | Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which… | ||
| CVE-2022-32138 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite. | ||
| CVE-2022-32137 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required. | ||
| CVE-2022-31805 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected. | ||
| CVE-2022-31804 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2022 | The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition. | ||
| CVE-2022-1965 | Hig | 0.53 | 8.1 | 0.01 | Jun 24, 2022 | Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required. | ||
| CVE-2022-32405 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4 | ||
| CVE-2022-32404 | — | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3 | |
| CVE-2022-32403 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4 | ||
| CVE-2022-32402 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4 | ||
| CVE-2022-32401 | — | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4 |
- risk 0.49cvss 7.5epss 0.01
When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which allocated from heap buffers.
- risk 0.49cvss 7.5epss 0.01
When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater than or equal to the size of the input_shape, it will access data outside of bounds of input_shape which allocated from heap buffers.
- risk 0.49cvss 7.5epss 0.01
When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers.
- risk 0.49cvss 7.5epss 0.01
When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will access data outside of bounds of heap allocated buffers.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.42cvss 7.5epss 0.01
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.
- risk 0.47cvss 7.2epss 0.01
The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks
- risk 0.53cvss 8.1epss 0.09
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their…
- risk 0.53cvss 8.1epss 0.01
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
- risk 0.53cvss 8.1epss 0.00
Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by…
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.49cvss 7.5epss 0.01
ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can…
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.
- risk 0.53cvss 8.1epss 0.00
A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.
- risk 0.49cvss 7.5epss 0.01
All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)
- risk 0.49cvss 7.5epss 0.01
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating crafted invalid emails.
- risk 0.51cvss 7.8epss 0.00
A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as…
- risk 0.49cvss 7.5epss 0.01
OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.
- risk 0.49cvss 7.5epss 0.03
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.
- risk 0.49cvss 7.5epss 0.03
OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.
- risk 0.51cvss 7.8epss 0.00
A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The vulnerability could allow local escalation of privilege. HPE has made the following software update to resolve the vulnerability in HPE Version Control…
- risk 0.49cvss 7.6epss 0.00
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive…
- risk 0.49cvss 7.5epss 0.01
Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script
- risk 0.48cvss 7.4epss 0.00
LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials.
- risk 0.54cvss 8.8epss 0.12
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.
- risk 0.49cvss 7.5epss 0.01
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling crafted invalid rgb(a) strings.
- risk 0.49cvss 7.5epss 0.02
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.
- risk 0.46cvss 7.1epss 0.00
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
- risk 0.57cvss 8.8epss 0.02
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
- risk 0.57cvss 8.8epss 0.01
In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker…
- risk 0.53cvss 8.1epss 0.01
Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which…
- risk 0.57cvss 8.8epss 0.01
In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.
- risk 0.57cvss 8.8epss 0.01
In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.
- risk 0.49cvss 7.5epss 0.01
In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.
- risk 0.49cvss 7.5epss 0.01
The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.
- risk 0.53cvss 8.1epss 0.01
Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4