← back
CVE-2014-2351

CSWorks SQL Injection

CVSS 7.5 EPSS 2.5%CWE-89
SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
CSWorks · CSWorks

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →