CVE-2020-28860

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
14/12/2020
Last modified:
15/12/2020

Description

OpenAssetDigital Asset Management (DAM) through 12.0.19 does not correctly sanitize user supplied input, incorporating it into its SQL queries, allowing for authenticated blind SQL injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openasset:digital_asset_management:*:*:*:*:*:*:*:* 12.0.19 (including)