CVE-2015-3424

HIGH

Accentis Content Resource Management System < 10-2015 - SQL Injection via SIDX Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0157
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
accentis/content_resource_management_system < 10-2015
Published Dec 09, 2019
Tracked Since Feb 18, 2026