VYPR

Pnpscada

by Sdg

CVEs (2)

  • CVE-2023-1934CriMay 12, 2023
    risk 0.67cvss 9.8epss 0.08

    The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying…

  • CVE-2020-24841CriFeb 16, 2021
    risk 0.64cvss 9.8epss 0.02

    PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.