CVE-2018-13792

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
10/02/2019
Last modified:
10/09/2020

Description

Multiple SQL injection vulnerabilities in the monitoring feature in the HTTP API in ABBYY FlexiCapture before 12 Release 2 allow an attacker to execute arbitrary SQL commands via the mask, sortOrder, filter, or Order parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:abbyy:flexicapture:*:*:*:*:*:*:*:* 12.0 (including) 12.0.2.1194 (excluding)