9.8
CVSSv3

CVE-2020-35545

Published: 17/12/2020 Updated: 21/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Time-based SQL injection exists in Spotweb 1.4.9 via the query string.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

spotweb project spotweb 1.4.9

Vendor Advisories

Debian Bug report logs - #977719 spotweb: CVE-2020-35545 Package: src:spotweb; Maintainer for src:spotweb is Jan-Pascal van Best <janpascal@vanbestorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 19 Dec 2020 14:45:02 UTC Severity: grave Tags: fixed-upstream, security, upstream Found in version ...

Exploits

Spotweb version 149 suffers from a remote SQL injection vulnerability Related CVE number: CVE-2020-35545 ...

Github Repositories

Spotweb 1.4.9 - 'search' SQL Injection

CVE-2020-35545 Spotweb 149 - 'search' SQL Injection