PoC Index

CVE-2018-12977

HIGH 8.8EPSS 1.5%

A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downloading Electronic Documents" section.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.46% chance of exploitation in the next 30 days, 72th percentile
Published
2018-07-09
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related