CVE-2016-9048

HIGH

ProcessMaker Enterprise Core 3.0.1.7-community - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0313

Scores

CVSS v3 7.4
EPSS 0.0080
EPSS Percentile 52.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-89
Status published
Products (1)
processmaker/processmaker 3.0.1.7 (2 CPE variants)
Published Sep 10, 2018
Tracked Since Feb 18, 2026