Showing 2 vulnerabilities on this page for ProcessMaker Enterprise

Signals CISA KEV Ransomware Nuclei
ProcessMaker vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.

CWE-502Sep 17, 2018
CVSS8.8v3.1EPSS2.21%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system.

CWE-89Sep 10, 2018
CVSS7.4v3.1EPSS0.798%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX