Vulnerability Details CVE-2022-44785
An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 53.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-44785
-
cpe:2.3:a:maggioli:appalti_&_contratti:9.12.2