CVE-2020-11942: SQL Injection
Published Apr 29, 2020
·Updated
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.
Affected Software
1 affected component
Opmantek Open-AudIT=3.2.2
Event History
Apr 29, 2020
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
Description
Frequently Asked Questions
1
What is CVE-2020-11942?
CVE-2020-11942 is a vulnerability discovered in Open-AudIT 3.2.2 that allows for multiple SQL injections.
2
How severe is CVE-2020-11942?
CVE-2020-11942 has a severity rating of 9.8 (critical).
3
How can I fix CVE-2020-11942?
To fix CVE-2020-11942, it is recommended to upgrade to Open-AudIT v3.3.0 or later.
4
What is the Common Weakness Enumeration (CWE) for CVE-2020-11942?
The Common Weakness Enumeration (CWE) for CVE-2020-11942 is CWE-89 (SQL Injection).
5
Where can I find more information about CVE-2020-11942?
You can find more information about CVE-2020-11942 in the Open-AudIT release notes for v3.3.0 and in the advisory by Core Security.