CRITICAL
ArmorX LisoMail - SQL Injection
Published Mar 18, 2020
9.8
CRITICALCVSS 3.1
EPSS 1.47%
Description
LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter manipulation.
Affected products
-
- Version 0StatusaffectedConstraints<2017
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Install the latest patch provided by the vendor.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-25187 Advisory
- https://gist.github.com/tonykuo76/50350af9b77eb51f5ab55964a35f47f2 x_refsource_MISCThird Party Advisory
- https://www.chtsecurity.com/news/2fd99e6e-819f-42b4-a7fe-6bc7eeae155c x_refsource_MISCThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-3437-17241-1.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-25187 | Advisory | |
| https://gist.github.com/tonykuo76/50350af9b77eb51f5ab55964a35f47f2 | x_refsource_MISCThird Party Advisory | |
| https://www.chtsecurity.com/news/2fd99e6e-819f-42b4-a7fe-6bc7eeae155c | x_refsource_MISCThird Party Advisory | |
| https://www.twcert.org.tw/tw/cp-132-3437-17241-1.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner twcert
Published Mar 18, 2020
Updated Sep 17, 2024
Reserved Dec 20, 2019
Link CVE-2020-3922
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-25187 Assigner twcert
Published Mar 18, 2020
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2020-25187