Paroiciel是法国Paroiciel公司的一个教区管理信息系统。 Paroiciel 11.20版本存在SQL注入漏洞,该漏洞源于zProIdPro参数存在SQL注入,可能导致经过身份验证的攻击者通过向zpro.php端点发送特制GET请求来执行任意SQL查询并提取敏感数据库信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-25428 | 8.2 HIGH | Paroiciel 11.20 SQL Injection via tRecIdListe Parameter |
| CVE-2018-25430 | 7.1 HIGH | Paroiciel 11.20 SQL Injection via eGeqIdEquipe Parameter |
No comments yet