peter bassill · operator
$ cve CVE-2018-20469 JSON

CVE-2018-20469 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 18.5% (pctl 97)

Patch early

A public exploit exists.

Description

An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS18.54% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2019-06-17
Last modified2026-06-17

Affected (1)

VendorProduct
sahiprosahi pro

Public exploits

SourceTitleDate
exploit-dbSahi pro 8.x - SQL Injection2019-06-18

References

→ the Explorer  ·  watch your stack  ·  NVD