CVE-2019-13957: SQL Injection
Published Oct 2, 2019
·Updated
In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.
Affected Software
1 affected component
Umbraco Umbraco=7.3.8
Event History
Oct 2, 2019
CVE Published
via MITRE·06:46 PM
Data Sourced
via MITRE·06:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13957?
The severity of CVE-2019-13957 is critical with a rating of 9.8.
2
How does SQL Injection occur in Umbraco 7.3.8?
In Umbraco 7.3.8, SQL Injection occurs in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the nodeName parameter.
3
What is the affected software version of CVE-2019-13957?
The affected software version of CVE-2019-13957 is Umbraco 7.3.8.
4
Where can I find more information about CVE-2019-13957?
You can find more information about CVE-2019-13957 at these references: [GitHub Gist](https://gist.github.com/shiham101/d1de44d1dcf2c33d401ef2f8cbb04f9f) and [Umbraco Website](https://our.umbraco.com/download/releases/738/).
5
What is the CWE category of CVE-2019-13957?
The CWE category of CVE-2019-13957 is CWE-89 (SQL Injection).