7.5
CVSSv2

CVE-2015-7299

Published: 21/10/2015 Updated: 31/03/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote malicious users to execute arbitrary SQL commands via the xml parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nintex k2 blackpearl 4.6.7

nintex k2 for sharepoint 4.6.7

nintex k2 smartforms 4.6.7

Exploits

K2 SmartForms, BlackPearl, and K2 for Sharepoint version 467 suffer from a boolean-based remote SQL injection vulnerability ...