Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
SD.NET RIM 4.7.3c - 'idtyp' SQL Injection
Vulnerability Description
SD.NET RIM versions before 4.7.3c contain a SQL injection vulnerability that allows attackers to inject malicious SQL statements through POST parameters 'idtyp' and 'idgremium'. Attackers can exploit this vulnerability by crafting specially formed POST requests to the /vorlagen/ endpoint, enabling unauthorized database manipulation and potential information disclosure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
STERNBERG SD.NET RIM 跨站请求伪造漏洞
Vulnerability Description
STERNBERG SD.NET RIM是英国STERNBERG公司的一个政务综合系统。 STERNBERG SD.NET RIM 4.7.3c之前版本存在跨站请求伪造漏洞,该漏洞源于攻击者可通过POST参数idtyp和idgremium注入恶意SQL语句,可能导致SQL注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A