- Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection.This issue affects Parkmatik: before 02.01-a51.
- Source
- iletisim@usom.gov.tr
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- iletisim@usom.gov.tr
- CWE-89
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:elra:parkmatik:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B0A96D1-3009-4A4D-9A28-B8E24A41EAD1",
"versionEndExcluding": "02.01-a51"
}
],
"operator": "OR"
}
]
}
]