CVE-2017-15875

CRITICAL

GPWeb 8.4.61 - SQL Injection via Password Recovery Checkemail Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.

Scores

CVSS v3 9.8
EPSS 0.0129
EPSS Percentile 67.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
sistemagpweb/gpweb 8.4.61
Published Dec 19, 2017
Tracked Since Feb 18, 2026