The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Title | NetVision Information airPASS - SQL injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published: 2025-01-16T01:29:25.439Z
Updated: 2025-01-16T15:41:05.904Z
Reserved: 2025-01-14T07:51:47.556Z
Link: CVE-2025-0455
Updated: 2025-01-16T15:41:01.753Z
Status : Received
Published: 2025-01-16T02:15:27.203
Modified: 2025-01-16T02:15:27.203
Link: CVE-2025-0455
No data.