Sunnet CTMS
cpe:2.3:a:sun.net:ctms:*:*:*:*:*:*:*
- < 1.0
A SQL injection vulnerability has been identified in all versions of the CTMS application developed by Sunnet. This vulnerability allows authenticated remote attackers to inject arbitrary SQL commands, which could be used to read, modify, or delete database contents.
Exploitation of this vulnerability could lead to unauthorized access to database information, allowing attackers to manipulate or delete data at will.
The vendor should have issued a patch. If not yet received, please reach out to the vendor directly.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.