Back

CVE-2020-8967

CRITICAL

There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information.

Published: Jun 1, 2020 Modified: Jun 17, 2026
CWE-89 CWE-89

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
gesio erp * < 11.2

GitHub Security Advisory GHSA-jx4q-cg94-9r74

There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection)...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 1.03%

Top 39% most likely to be exploited

Threat Score 40.3 / 100

Data Sources

NVD EPSS GitHub