Vulnerability Details CVE-2022-44785
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.5%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-44785
-
cpe:2.3:a:maggioli:appalti_&_contratti:9.12.2