CVE-2020-28860

OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:openasset:digital_asset_management:*:*:*:*:*:*:*:*

Information

Published : 2020-12-14 12:15

Updated : 2020-12-15 08:41


NVD link : CVE-2020-28860

Mitre link : CVE-2020-28860


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

openasset

  • digital_asset_management