CVE-2020-6114

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
10/07/2020
Last modified:
12/05/2022

Description

An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:icehrm:icehrm:26.6.0.os:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools