CVE-2017-6550: Kinsey Infor-Lawson

Critical severity, CVSS 9.8. EPSS: 4% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.

Affected products

  • Kinsey Infor-Lawson: affected versions not specified

Published 2017-03-20. Last modified 2026-06-17.