OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-12-14T19:33:22

Updated: 2024-08-04T16:40:59.818Z

Reserved: 2020-11-16T00:00:00

Link: CVE-2020-28860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-14T20:15:12.810

Modified: 2020-12-15T16:41:52.943

Link: CVE-2020-28860

cve-icon Redhat

No data.