Filtered by vendor Bladex
Subscriptions
Filtered by product Springblade
Subscriptions
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-47458 | 1 Bladex | 1 Springblade | 2024-11-21 | 9.8 Critical |
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework. | ||||
CVE-2023-40788 | 1 Bladex | 1 Springblade | 2024-11-21 | 5.3 Medium |
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs | ||||
CVE-2023-40787 | 1 Bladex | 1 Springblade | 2024-11-21 | 9.8 Critical |
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | ||||
CVE-2022-27360 | 1 Bladex | 1 Springblade | 2024-11-21 | 9.8 Critical |
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. |
Page 1 of 1.