Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy STER
- < 9.5
A SQL injection vulnerability exists in the STER application, developed by the Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy. This vulnerability arises from improper handling of user input in multiple search filters, allowing authenticated attackers to execute SQL injection attacks. Exploitation of this vulnerability could lead to unauthorized access to sensitive data, including information belonging to other users or any data the application can access. All versions of STER prior to 9.5 are affected.
Exploitation of this vulnerability allows for SQL injection, enabling attackers to manipulate database queries and potentially access or modify sensitive data.
Users can upgrade to STER version 9.5 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.