← Back to browse · API

CVE-2017-14851

Severity
CRITICAL
CVSS
9.8
EPSS
0.04065
Risk score
40.62
CISA KEV
No
PoC
No
Published
2019-06-03
Modified
2026-06-02
First seen
2026-08-07
Aliases
EUVD-2017-6340, GHSA-2HGQ-6HRQ-XXF4
Products
n/a:n/a n/a
Sources
euvd EUVD-2017-6340

Description

A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.

References