Synnefo Internet Management Software
cpe:2.3:a:synnefoims:internet_management_software:*:*:*:*:*:*:*
- <= 2023
A SQL injection vulnerability has been identified in Synnefo Internet Management Software (IMS) versions through 2023. The issue arises from inadequate input validation in a specific API endpoint, which allows attackers to manipulate SQL queries by sending crafted input. Exploitation of this vulnerability could result in unauthorized access to database records with administrative privileges, potentially leading to further privilege escalation and the execution of arbitrary operating system commands.
Exploitation of this vulnerability could allow an attacker to access sensitive database records with administrative rights, escalate privileges, and execute arbitrary commands on the operating system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.