CVE-2018-12977

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
09/07/2018
Last modified:
05/09/2018

Description

A SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by pulling information from the database with the "cddocument" parameter in the "Downloading Electronic Documents" section.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:softexpert:excellence_suite:2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools