GestSup
cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*
- <= 3.2.56
A SQL injection vulnerability has been identified in GestSup versions through 3.2.56. This issue arises in the search bar functionality, where user-controlled input is directly included in SQL queries without proper sanitization. As a result, an authenticated attacker could manipulate database queries, potentially leading to unauthorized access to or modification of database contents, depending on their database privileges.
Exploitation of this vulnerability allows for SQL injection, which could lead to unauthorized access to or modification of database contents.
Users are advised to update to GestSup version 3.2.57 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.