Vulnerability Description
A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Terrasoft | Bpm Online Crm System Sdk | 7.13 |
Related Weaknesses (CWE)
References
- https://medium.com/%40sorokinpf/bpmonline-sql-injection-607916447e30
- https://medium.com/%40sorokinpf/bpmonline-sql-injection-607916447e30
FAQ
What is CVE-2019-15301?
CVE-2019-15301 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13 allows attackers to execute arbitrary SQL commands via the value parameter.
How severe is CVE-2019-15301?
CVE-2019-15301 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-15301?
Check the references section above for vendor advisories and patch information. Affected products include: Terrasoft Bpm Online Crm System Sdk.