vendor:
evalSMSI
by:
7.5
CVSS
HIGH
Authentication bypass, SQL Injection, HTML Injection
CWE
Product Name: evalSMSI
Affected Version From:
Affected Version To: evalSMSI 2.2.00
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
Multiple vulnerabilities in evalSMSI
Attackers can gain administrative access, execute arbitrary script code in the browser, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Mitigation:
Upgrade to evalSMSI 2.2.00 or later.