GHSA-7q5m-m6v8-m536HighCVSS 8.8
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied...
🔗 CVE IDs covered (1)
📋 Description
OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2020-28860
- https://www.themissinglink.com.au/security-advisories-cve-2020-28860
- http://openasset.com
- http://packetstormsecurity.com/files/160459/OpenAsset-Digital-Asset-Management-SQL-Injection.html
- http://seclists.org/fulldisclosure/2020/Dec/21
- https://github.com/advisories/GHSA-7q5m-m6v8-m536