Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services Inc. PaperWork allows Blind SQL Injection, SQL Injection.This issue affects PaperWork: from 6.1.0.9390 before 6.1.0.9398.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CWE - 564 - SQL Injection: Hibernate
Product status
6.1.0.9390 (custom) before 6.1.0.9398
Credits
Murat ERDEMİR
References
www.usom.gov.tr/bildirim/tr-25-0381