CVE-2016-9048
HIGHProcessMaker Enterprise Core 3.0.1.7-community - SQL Injection
Title source: llmDescription
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain setups access the underlying operating system.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0313
Scores
CVSS v3
7.4
EPSS
0.0080
EPSS Percentile
52.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Details
CWE
CWE-89
Status
published
Products (1)
processmaker/processmaker
3.0.1.7 (2 CPE variants)
Published
Sep 10, 2018
Tracked Since
Feb 18, 2026