CVE-2020-12870

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
30/09/2020
Last modified:
02/10/2020

Description

RainbowFish PacsOne Server 6.8.4 allows SQL injection on the username parameter in the signup page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rainbowfishsoftware:pacsone_server:6.8.4:*:*:*:*:*:*:*