Vulnerability Description
Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Realization | Concerto Critical Chain Planner | 5.10.8071 |
Related Weaknesses (CWE)
References
- https://github.com/IckoGZ/CVE-2019-13027/blob/master/README.mdExploitThird Party Advisory
- https://github.com/IckoGZ/CVE-2019-13027/blob/master/README.mdExploitThird Party Advisory
FAQ
What is CVE-2019-13027?
CVE-2019-13027 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.
How severe is CVE-2019-13027?
CVE-2019-13027 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-13027?
Check the references section above for vendor advisories and patch information. Affected products include: Realization Concerto Critical Chain Planner.