CVE-2019-11600
high · 8.1A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.
8.1
CVSS
80.0%
EPSS (exploit prob.)
100th
EPSS percentile
2019-05-13
Published
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openproject | openproject | >= 5.0.0, < 8.3.2 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/152806/OpenProject-8.3.1-SQL-Injection.html
- http://seclists.org/fulldisclosure/2019/May/7
- https://groups.google.com/forum/#%21msg/openproject-security/XlucAJMxmzM/hESpOaFVAwAJ
- https://seclists.org/bugtraq/2019/May/22
- https://www.openproject.org/release-notes/openproject-8-3-2/
- http://packetstormsecurity.com/files/152806/OpenProject-8.3.1-SQL-Injection.html
- http://seclists.org/fulldisclosure/2019/May/7
- https://groups.google.com/forum/#%21msg/openproject-security/XlucAJMxmzM/hESpOaFVAwAJ
- https://seclists.org/bugtraq/2019/May/22
- https://www.openproject.org/release-notes/openproject-8-3-2/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-11600