PoC Index

CVE-2019-11600

HIGH 8.1EPSS 80.0%

A SQL injection vulnerability in the activities API in OpenProject before 8.3.2 allows a remote attacker to execute arbitrary SQL commands via the id parameter. The attack can be performed unauthenticated if OpenProject is configured not to require authentication for API access.

CVSS v3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
79.96% chance of exploitation in the next 30 days, 100th percentile
Nuclei
high
Published
2019-05-13
Updated
2024-08-04

Proof-of-concept exploits (3)

Nuclei templates (1)

ExploitDB entries (1)

References

Related