PT-2020-14864 · Saint · Saint Security Suite
Published
2020-08-10
·
Updated
2020-08-11
·
CVE-2020-16277
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAINT Security Suite versions 8.0 through 9.8.20
Description
The issue is related to an SQL injection vulnerability in the Analytics component. This vulnerability allows a remote, authenticated attacker to gain unauthorized access to the database.
Recommendations
For versions 8.0 through 9.8.20, update to a version that contains a fix for this issue to prevent unauthorized database access.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saint Security Suite