CVE-2015-5376: Gsi-Office Winpat Portal
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
SQL injection vulnerability in the login form in GSI WiNPAT Portal 3.2.0.1001 through 3.6.1.0 allows remote attackers to execute arbitrary SQL commands via the username field.
Affected products
- Gsi-Office Winpat Portal: version 3.2.0.1001 only; version 3.6.1.0 only
Published 2017-10-18. Last modified 2026-06-17.