Metrics
Affected Vendors & Products
Wed, 29 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 29 Jan 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | ESAFENET CDG sdTodoDetail.jsp sql injection | |
Metrics |
cvssV4_0
|
cvssV3_0
|
Wed, 29 Jan 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as critical, was found in ESAFENET CDG V5. Affected is an unknown function of the file /sdTodoDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-01-29T00:00:16.765Z
Updated: 2025-01-29T14:11:54.150Z
Reserved: 2025-01-28T14:34:22.328Z
Link: CVE-2025-0792

Updated: 2025-01-29T14:11:47.719Z

Status : Received
Published: 2025-01-29T00:15:08.653
Modified: 2025-01-29T15:15:18.653
Link: CVE-2025-0792

No data.