OSV 1.4.0 · unreviewed · 修改于 2022-02-03 08:00
发布时间
2022-01-29 08:00
GitHub 审查时间
—
NVD 发布时间
2022-01-29 03:15
源文件
advisories/unreviewed/2022/01/GHSA-jx6q-6477-j7q5/GHSA-jx6q-6477-j7q5.json
SQL injection in the ID parameter of the UploadedImageDisplay.aspx endpoint of SelectSurvey.NET before 5.052.000 allows a remote, unauthenticated attacker to retrieve data from the application's backend database via boolean-based blind and UNION injection.
该公告没有提供结构化的受影响软件包信息。