vendor:
SQL Monitor
by:
geeklinuxman@gmail.com
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: SQL Monitor
Affected Version From: 12.1.31.893
Affected Version To: 12.1.31.893
Patch Exists: YES
Related CWE: CVE-2022-47870
CPE: a:red_gate:sql_monitor:12.1.31.893
Platforms Tested: Windows OS
2022
SQL Monitor 12.1.31.893 – Cross-Site Scripting (XSS)
Cross Site Scripting (XSS) in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows remote attackers to inject arbitrary web Script or HTML via the returnUrl parameter.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.