Blind SQL injection in a service running in Snow Software...
High severity
Unreviewed
Published
Aug 11, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Aug 11, 2023
Published to the GitHub Advisory Database
Aug 11, 2023
Last updated
Apr 4, 2024
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
References