Filtered by vendor Bladex Subscriptions
Filtered by product Springblade Subscriptions
Total 4 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-27360 1 Bladex 1 Springblade 2024-08-03 9.8 Critical
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
CVE-2023-47458 1 Bladex 1 Springblade 2024-08-02 9.8 Critical
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
CVE-2023-40787 1 Bladex 1 Springblade 2024-08-02 9.8 Critical
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.
CVE-2023-40788 1 Bladex 1 Springblade 2024-08-02 5.3 Medium
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs