2024-05-28 14:03:31 +00:00

28 lines
769 B
JSON

{
"id": "CVE-2024-36428",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-05-27T23:15:13.120",
"lastModified": "2024-05-28T12:39:28.377",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection."
},
{
"lang": "es",
"value": "OrangeHRM 3.3.3 permite la inyecci\u00f3n SQL sortOrder de admin/viewProjects."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/4rdr/proofs/blob/main/info/OrangeHRM_3.3.3_SQLi_via_sortOrder.md",
"source": "cve@mitre.org"
},
{
"url": "https://sourceforge.net/projects/orangehrm/files/stable/3.3.3/",
"source": "cve@mitre.org"
}
]
}