PT-2022-7915 · Navetti · Navetti Pricepoint

W. Schober

·

Published

2022-06-13

·

Updated

2022-10-21

·

CVE-2017-20042

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Navetti PricePoint version 4.6.0.0
Description A critical issue has been found in the software, affecting an unknown functionality. This issue leads to sql injection (Blind) and can be exploited remotely.
Recommendations For Navetti PricePoint version 4.6.0.0, upgrade to version 4.7.0.0 to address this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2017-20042

Affected Products

Navetti Pricepoint