CVE-2018-15918

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
05/09/2018
Last modified:
05/07/2022

Description

An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jorani_project:jorani:0.6.5:*:*:*:*:*:*:*