CVE-2022-27360

CRITICAL

SpringBlade <= 3.2.0 - SQL Injection via customSqlSegment

Title source: llm
STIX 2.1

Description

SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://forum.butian.net/share/1089
Permissions Required, Third Party Advisory x_refsource_misc
https://saber.bladex.vip/#/login

Scores

CVSS v3 9.8
EPSS 0.0063
EPSS Percentile 70.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
bladex/springblade 3.2.0
Published May 05, 2022
Tracked Since Feb 18, 2026