packetstormsecurity.com
http://packetstormsecurity.com/files/150004/SaltOS-Erp-Crm-3.1-r8126-SQL-Injection.html CVE-2018-18763
CRITICAL
SaltOS Erp Crm 3.1 r8126 - SQL Injection (2)
Record summary
CVE-2018-18763 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSaltOS Erp Crm 3.1 r8126 - SQL Injection (2)ExploitDB exploitby Ihsan SencanNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-18763 45733exploit
https://www.exploit-db.com/exploits/45733