← back
CVE-2020-26525

CVE-2020-26525

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 25%
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
Damstra Smart Asset 2020.7 has SQL injection via the API/api/Asset originator parameter. This allows forcing the database and server to initiate remote connections to third party DNS servers.
Affected products
n/a · n/a