漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SQL Injection in SIMPLE.ERP
Vulnerability Description
SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user a malicious query injection. Potential exploitation is limited by the 20-character limit in form fields. Identified use case allows to delete tables with a name of maximum 6 characters. We weren't able to identify a way to exfiltrate data within query character limit. This issue affects SIMPLE.ERP in versions before 6.30@a04.3.
CVSS Information
N/A
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
SIMPLE.ERP SQL注入漏洞
Vulnerability Description
SIMPLE.ERP是SIMPLE公司的一个电子商务平台。 SIMPLE.ERP 6.30@a04.3之前版本存在SQL注入漏洞,该漏洞源于仓库文档过滤表单存在SQL注入漏洞,可能导致表删除。
CVSS Information
N/A
Vulnerability Type
N/A