PT-2026-42742 · Ster · Ster
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
STER versions prior to 9.5
Description
Improper neutralization of user input within multiple Search Filters allows an authenticated attacker to perform SQL injection. This can lead to the unauthorized viewing of sensitive information, including data belonging to other users or any other data accessible by the application.
Recommendations
Update to version 9.5.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ster