Description
IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- ibm / concert1.0.0 – 1.0.0
- ibm / concert2.3.1 – 2.3.1
- ibm / concert1.0.0 – 2.3.1
References
Updated 11m ago · 8 sources