Vulnerability Details CVE-2022-44785
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.9%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-44785
-
cpe:2.3:a:maggioli:appalti_&_contratti:9.12.2