Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1108 Exploit Technical Description Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: talos

Published: 2020-09-24T14:13:06

Updated: 2020-09-24T14:13:06

Reserved: 2020-05-26T00:00:00


Link: CVE-2020-13505

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-09-24T15:15:13.783

Modified: 2020-09-25T15:04:25.270


Link: CVE-2020-13505

JSON object: View

cve-icon Redhat Information

No data.

CWE