Vulnerability Details CVE-2019-11363
A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary SQL commands via the AgentConsole/UserGroupQuery.php ShowUser parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.8%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2019-11363
-
cpe:2.3:a:prophecyinternational:snare_central:7.1.1
-
cpe:2.3:a:prophecyinternational:snare_central:7.1.2
-
cpe:2.3:a:prophecyinternational:snare_central:7.1.3
-
cpe:2.3:a:prophecyinternational:snare_central:7.1.4
-
cpe:2.3:a:prophecyinternational:snare_central:7.2.0
-
cpe:2.3:a:prophecyinternational:snare_central:7.3.0
-
cpe:2.3:a:prophecyinternational:snare_central:7.4.1
-
cpe:2.3:a:prophecyinternational:snare_central:7.4.2
-
cpe:2.3:a:prophecyinternational:snare_central:7.4.3
-
cpe:2.3:a:prophecyinternational:snare_central:7.4.4