CVE-2020-13567
- EPSS 0.05%
- Veröffentlicht 18.04.2022 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:30
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
CVE-2020-13566
- EPSS 0.06%
- Veröffentlicht 13.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:30
SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability In admin/edit_group.php, when the POST parameter action is “Delete”...
CVE-2020-13568
- EPSS 0.24%
- Veröffentlicht 13.04.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:31
SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability in admin/edit_group.php, when the POST parameter action is “Submit”,...
CVE-2020-13565
- EPSS 3.34%
- Veröffentlicht 10.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:01:30
An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP request can redirect ...
CVE-2020-13562
- EPSS 70.98%
- Veröffentlicht 01.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:30
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnaerability in the phpGA...
CVE-2020-13563
- EPSS 29.51%
- Veröffentlicht 01.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:30
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGAC...
CVE-2020-13564
- EPSS 29.51%
- Veröffentlicht 01.02.2021 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:01:30
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a crafted URL to trigger this vulnerability in the phpGAC...