CVE-2020-8967
Summary
| CVE | CVE-2020-8967 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-01 14:15:00 UTC |
| Updated | 2020-06-04 16:20:00 UTC |
| Description | There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GESIO SQL injection vulnerability | INCIBE-CERT | CONFIRM | www.incibe-cert.es | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Francisco Palma, Luis Vázquez and Diego León.
There are currently no legacy QID mappings associated with this CVE.