What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview interview allows SQL Injection.This issue affects Interview: from n/a through <= 1.01.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in proxymis Interview interview allows SQL Injection.This issue affects Interview: from n/a through <= 1.01.
Explanation of Vulnerability in Simple Terms
Proxymis Interview versions 1.01 and earlier contain a SQL injection vulnerability accessible to authenticated users. An attacker with low-level account access can inject malicious SQL queries to read sensitive data from the database, including information outside their normal access scope. The vulnerability requires valid login credentials but no additional user interaction.
What an attacker can do
Read sensitive data from the database, including records outside their normal access permissions.
Potential impact on your site
Unauthorized data disclosure affecting all users and records in the database if the application stores sensitive information.
Conditions required to exploit
Valid user account with low-level privileges; network access to the application.
Key dates
External resources
Related vulnerabilities