Latest Security News about cve 2020 5292

Contact US For API Security>

Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability.

Overview : Leantime before versions 2.0.15 and 2.1-beta3 has a SQL Injection vulnerability. The impact is high. Malicious users/attackers can execute arbitrary SQL queries negatively affecting the confidentiality, integrity, and availability of the site. Attackers can exfiltrate data like the users' and administrators' password hashes, modify data, or drop tables. The unescaped parameter is "searchUsers" [...]