CVE-2020-7356
critical · 10CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code and execute SYSTEM commands.
10
CVSS
14.0%
EPSS (exploit prob.)
96th
EPSS percentile
2020-08-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Weaknesses
CWE-89
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| cayintech | xpost | 1.0 |
| cayintech | xpost | 2.0 |
| cayintech | xpost | 2.5.18103 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-7356