CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
A command injection exists in GitLab CE/EE
Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.
Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.
Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.
The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.
BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during [2019]. Notes: none.
HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.
idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.
OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.
